Clear licensing, a usable README, and an unarchived repository provide useful adoption context. However, the last release was over seven years ago and the repository has had no commits in nearly seven years, with no security policy or scanning.
40%
Total Score
63
100
81
75
There have been 29 releases since September 2016, but the latest release was in May 2019 and there were no releases in the last 12 months. That long release gap is strong evidence of abandonment risk.
The repository had zero commits and zero active maintainers in the last three months; its last push was nearly seven years ago. This is the strongest evidence that fixes and compatibility updates may no longer arrive.
Four issues remain open and there were no new or closed issues or pull requests in the last month, consistent with an inactive project and adding to the maintenance concern.
Composer build tooling is present, but no security scanning tools are reported. For a payment integration, that missing security automation is a real hygiene gap, though it is secondary to the inactivity.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or communicating security handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mangopay/php-sdk-v2 Version >=2.0 | — | — |
troopers/ajax-bundle Version ~1.2 | — | — |
symfony/framework-bundle Version ~3.4|~4 | — | — |
stof/doctrine-extensions-bundle Version ~1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.