The repository has no tests or security scanning, and its tiny footprint provides little evidence of ongoing care. A readable README, release notes, and organization backing improve transparency but do not offset the long maintenance gap.
34%
Total Score
0
71
50
The package has had four releases since November 2016 and none in the last 12 months; the latest release is nearly 10 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push in November 2016. No provided signal shows current maintenance activity.
The repository has one star, one watcher, and no forks. Popularity is only supporting evidence, but these numbers provide little evidence of a broad maintainer or user community.
Composer is used as a build tool, but no security scanning tools are present. The absence of scanning is a hygiene concern, though it does not by itself show the release is unsafe.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a maintenance and transparency gap for a payment-related library.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.