Healthy and actively maintained, with a clear source repository and recent release activity. Treat this alpha release as less stable than a production release, and note that recent work is concentrated in one contributor despite organizational backing.
78%
Total Score
88
50
88
67
The plugin declares 35 runtime dependencies across Sylius, Symfony, Payum, and Quickpay components. This is a substantial integration surface, but it is consistent with a payment plugin rather than evidence of abandonment by itself.
All 94 recent commits came from one contributor, creating a real continuity risk. The organization-owned repository provides some ability to hand off maintenance, but no second active contributor is shown.
The repository uses Composer build tooling, but no security-scanning tools were detected. That is a transparency and assurance gap, though it does not outweigh the strong maintenance evidence.
No security policy was found, leaving vulnerability-reporting expectations unclear for a payment integration.
Neither workflow declares top-level token permissions. No workflow requests top-level write access, but explicit least-privilege permissions would provide stronger assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
twig/twig Version ^2.15 || ^3.0 | — | — |
payum/payum Version ^1.6 | — | — |
sylius/core Version ^1.0 | — | — |
symfony/form Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.