The package includes tests, a clear MIT license, and a matching source repository owned by an organization. Its small audience and absent security policy limit transparency, while recent repository activity is not reflected in releases.
68%
Total Score
75
100
81
75
The package has existed since 2017 and reached a latest release on July 24, 2025, but made no releases in the last 12 months. That indicates a meaningful maintenance slowdown for a payment integration, though the package is not abandoned based on this signal alone.
There were zero commits and zero active maintainers in the last three months. For a payment gateway integration, that weakens confidence that defects and compatibility changes will be addressed promptly.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these low numbers provide little additional evidence of community resilience.
Composer build tooling is present, but no security scanning tools were detected. This is a modest supply-chain hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, although it does not by itself indicate poor code quality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~3.0 | — | — |
judopay/judopay-sdk Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.