Release notes, a usable README, and Psalm scanning provide useful project transparency. Recent commit activity is absent, while workflow hygiene is weak because all ten actions are unpinned and the audit found high-confidence template-injection and artipacked issues.
58%
Total Score
75
92
25
All 10 analyzed action references are unpinned, and the audit found high-confidence template-injection findings in release automation plus an artipacked finding in pull-request automation. There are no untrusted-checkout or script-injection findings, but the workflow setup still warrants caution.
The package is 525 days old with four releases and two releases in the last 12 months, indicating a real but relatively slow release cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the release history shows the project was updated recently.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented for a payment-related integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tpaycom/magento2basic Version ^2.8.0 | — | — |
hyva-themes/magento2-theme-module Version ^1.3.11 | — | — |
hyva-themes/magento2-hyva-checkout Version ^1.3.0 | — | — |
hyva-themes/magento2-compat-module-fallback Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.