The package includes a README and changelog, uses an MIT declaration, and has no install-time scripts. Security scanning is absent, and recent work is handled by one contributor, so maintenance continuity depends heavily on the organization.
67%
Total Score
75
88
75
All 3 recent commits came from one contributor, creating concentration risk; organization ownership partly compensates by providing a potential maintenance handoff path.
The repository had 3 commits in the last 3 months, showing some recent activity, but the volume is modest for an API client.
Composer is used for builds, but no security-scanning tools were detected, leaving a repository-level assurance gap.
The repository has no security policy, making vulnerability reporting and response expectations less transparent for a package that handles payment API integrations.
The assessed release is stable and not a prerelease, but the reported latest version is 2.0.11, lower than the assessed 3.0.3, which makes registry version metadata difficult to reconcile.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
nyholm/psr7 Version ^1.3 | — | — |
psr/http-client Version ^1.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
guzzlehttp/guzzle Version >=6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.