The repository is not archived and includes tests, a README, and a recognized MIT license. However, the registry has had no release in over seven years, and recent repository activity is absent, making continued compatibility and support uncertain.
48%
Total Score
25
100
81
75
The package has had no release in over seven years despite being mature, and all four releases were concentrated in a very short period. This is strong evidence of release abandonment.
There were zero commits and zero active maintainers in the last three months. Together with the stale registry release history, this raises abandonment and maintenance risk.
The repository is owned by an individual user rather than an organization, so the single registry maintainer is consistent with the available ownership context but offers limited visible institutional backing.
The repository uses Composer but reports no security-scanning tools. This is a modest supply-chain hygiene gap, though it is less significant than the release and activity history.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a genuine transparency gap for a payment-integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ixudra/curl Version ^6.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.