Healthy and actively usable, with a small-maintainer caveat. It has frequent releases, a current unarchived repository, tests, documentation, and clear licensing, but all recent commits come from one contributor and the repository does not clearly identify this package.
78%
Total Score
50
89
50
One contributor made all two recent commits, leaving maintenance dependent on a single active individual. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to compensate for this concentration.
Only two commits were made in the last three months, which shows some activity but a relatively thin recent maintenance cadence for a package with a large integration surface.
The repository name does not match the package name and its README does not mention the package, so the link between the source repository and this release is not clearly demonstrated.
The repository has one star, zero forks, and one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of broad external review or adoption.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in payment-related code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
payum/stripe Version ^1.7 | — | — |
florianv/swap Version ^4.5 | — | — |
payum/offline Version ^1.7 | — | — |
sylius/currency Version ^2.0 | — | — |
sylius/customer Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.