Composer metadata is simple and the MIT license is declared. The source repository has no security policy and does not clearly identify this package, leaving maintenance and provenance concerns unresolved.
40%
Total Score
0
70
67
The repository recorded zero commits and zero active maintainers in the last three months. With only one release, this provides no evidence of ongoing maintenance.
The artifact contains only two files, including composer.json and a compressed archive, providing very little visible implementation or documentation context for a library dependency.
The package has no README, tests, or changelog. For a payment-integration library, the missing README is a meaningful consumer and transparency gap, while absent tests and changelog files are not expected in every published artifact.
This release is the package's only release, published 111 days ago, so there is little history demonstrating sustained maintenance.
The linked repository name does not match the package name, and the package could not be confirmed in its README. This weakens confidence that the repository clearly backs this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
endroid/qr-code Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.