The MIT license and matching repository make its provenance clear. Its very short README, one-person ownership, and lack of security tooling provide limited support for a package handling PayPal subscriptions.
38%
Total Score
0
100
69
75
This package has had only one release, published in June 2020, with no releases in the following six years. That is strong evidence of abandonment for a dependency expected to track a changing payment API.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap and leaving current maintenance capacity un demonstrated.
The artifact includes a README, and the absence of tests or a changelog is normal for published package contents. However, the README is only 69 characters and gives consumers little integration guidance.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful community-maintenance signal.
The linked repository has no security policy, reducing transparency for reporting issues in a package that handles payment-related integrations. This is secondary to the much stronger maintenance concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.