Recent releases, thorough tests, and release notes support dependable maintenance. Small popularity and contributor numbers limit broader confidence, while the project’s security policy is absent.
78%
Total Score
88
100
83
75
The package declares GPL-3.0-or-later and includes a license file, but the artifact also contains detected GPL-2.0 text that the declaration does not cover. The declaration and repository license evidence compensate for the presence gap, but the mismatch warrants caution.
Two contributors are active, but one produced about 73% of the last three months’ commits. The organization backing provides some handoff capacity, yet the observed activity remains concentrated.
The repository name does not match the package name and its README does not mention the package. Although a naming difference can occur in a related repository, the lack of an explicit package reference leaves package-to-source identity less transparent.
The repository has only 2 stars and 5 forks, so external adoption evidence is limited. Popularity is supporting evidence rather than a requirement, and the active release and commit signals offset much of this concern.
The repository has no published security policy. This is a transparency gap for a payment integration, although active maintenance and security scanning provide partial compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
composer/installers Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.