The single-release history and inactive repository leave little evidence of ongoing maintenance. The license files are present, and the package is not deprecated or archived, but its lone maintainer and absent security policy add concern.
38%
Total Score
50
38
50
This is the package's only release, published over three years ago, with no releases in the last 12 months. That provides little evidence of ongoing maintenance for a payment plugin.
License files are present, so the release is licensed, but the manifest declares LGPL-3.0-or-later while the detected artifact license is GPL-3.0. That mismatch deserves clarification before adoption.
One registry maintainer account is responsible for publishing the package, leaving a thin publishing base. The linked project is user-owned rather than organization-backed, so there is little provided evidence of broader continuity.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no additional sign of community review or support.
The repository is not archived, which is positive, but its last push was over three years ago. That inactivity supports a meaningful abandonment concern despite the repository remaining available.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.