The project has a long release history, frequent recent releases, and recent changes from two contributors. Its automation and package-to-repository identity need tightening before treating builds as fully trustworthy.
64%
Total Score
83
100
94
75
Two contributors were active in the last three months, which provides some handoff capacity, although one contributor made 75% of commits. The concentration is a mild resilience concern rather than a severe single-maintainer risk.
The repository name does not match the package name and its README does not mention the package. Although name differences can be normal, both indicators together leave the package-to-source relationship insufficiently clear.
No repository security policy was found. For a payment module handling transaction and token flows, the lack of a documented vulnerability-reporting path reduces transparency.
All four workflows were analyzed, but all 10 action references are unpinned, and high-confidence template-injection findings appear in the release workflow while an artipacked finding appears in pull-request automation. These workflow weaknesses warrant caution around build and release integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1 | — | — |
tpay-com/tpay-php Version ^2.4.7 | — | — |
tpay-com/tpay-openapi-php Version ^2.4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.