The package has a clear MIT license, a focused artifact, and no install-time scripts. Its repository is inactive and lacks a security policy, so ongoing compatibility support is uncertain.
42%
Total Score
50
70
75
The package has 17 releases, but all activity ended in June 2022 and there were no releases in the last 12 months. This is strong evidence of abandonment risk for a payment gateway integration.
There were zero commits and zero active maintainers in the last 3 months, consistent with the repository having received no updates for over four years. This materially lowers confidence in ongoing maintenance.
The repository is not archived, which is a positive, but it was last pushed in June 2022. Its visible availability does not offset the prolonged inactivity.
The repository has no published security policy. That is a transparency and response-process gap for a package handling payment integrations, though it is less severe than the sustained inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.