The package has a substantial README, tests, and matching Apache-2.0 licensing. Recent registry releases and organization backing help, but the repository shows no commits in the last three months and has no security scanning or security policy.
68%
Total Score
83
100
88
75
The repository recorded zero commits and zero active maintainers in the last three months, despite a recent registry release; this weakens evidence of continuing source maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful security-process gap for a payment SDK.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations for a payment integration library.
The assessed release is not a prerelease and recent prerelease share is zero, supporting stable consumption; the reported latest version being 4.9.2 is inconsistent with the assessed 5.2.2 and modestly reduces confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.5 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
guzzlehttp/guzzle Version ^7.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.