The package has recent releases and an active, non-archived repository, with a matching project name and organization backing. It lacks a README, tests, changelog, and security policy, while recent repository activity is quiet; inspect integration behavior before adopting it.
62%
Total Score
67
100
81
50
Only one account has registry publish access, which is a narrow publishing base. The organization-owned repository provides some backing, so this is a modest resilience concern rather than a standalone abandonment signal.
The artifact has no README, tests, or changelog, and the repository reports none of these either. Missing tests and changelog are normal packaging practice, but the absent README is a real usability and transparency gap for a library consumers must integrate.
There were no commits and no active maintainers in the last 3 months. The recent release push and release history partly compensate, but the lack of ongoing source activity lowers confidence in maintenance continuity.
The repository uses Composer for its build tooling, but no security scanning tools were detected. The missing scanning is a hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. For a payment-processing integration, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version 1.7 | — | — |
omnipay/common Version ^3.2.0 | — | — |
php-http/httplug Version ^2.4 | — | — |
symfony/http-client Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.