The repository includes tests, a substantial README, matching source, and a correct MIT license; organization backing and dependency scanning add useful transparency. This is a first release with no established commit history, and its two workflow actions are unpinned.
65%
Total Score
75
100
94
67
This is the package's first release, published on the assessment date, so there is no release history to demonstrate sustained maintenance. Its stable 1.0.0 version is a modest compensating signal, not evidence of maturity.
No commits or active maintainers were recorded during the last three months. Because the repository is newly released, this may reflect its age, but it still leaves maintenance capacity unproven.
The repository has no security policy, which is a minor transparency gap for a payment-focused library, though it does not by itself indicate abandonment.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or high-confidence findings. However, both analyzed action references are unpinned, leaving avoidable build reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ttpryg/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.