Quickpay gateway for Payum
68%
Total Score
caution
Usable with caveats: one contributor owns all recent commits, and this release is still a release candidate.
One contributor made all 65 commits in the last 3 months, creating a clear continuity risk; organization backing partly reduces the handoff concern but does not remove concentration.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
This is a release candidate rather than a stable release, and 40% of recent releases are prereleases, so compatibility may still change despite the mature major line.
The sole workflow was fully analyzed with no injection or high-severity findings, but all 19 action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
payum/core Version ^1.7.5 | — | — |
setono/quickpay-php-sdk Version ^1.2 | — | — |
php-http/message-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.