Usable with caveats: the package is actively maintained and well documented, with tests, a clear license, and a repository that matches the package. It is young, has only two releases, and all recent commits come from one maintainer, so long-term continuity is not yet proven.
68%
Total Score
63
100
78
90
One registry maintainer matches the repository owner, which is consistent with an individual project but leaves publishing and release continuity concentrated in one account.
The registry and repository are owned by the same individual account, confirming direct ownership but offering no organizational backing beyond the single maintainer.
The package is only 67 days old and has two releases, with releases about 67 days apart. This provides limited evidence about sustained maintenance and release reliability.
All seven recent commits came from one contributor, leaving maintenance dependent on a single person and creating a meaningful continuity risk for a payment SDK.
The repository has one star and no forks or watchers. This is weak supporting evidence, but popularity alone does not make a small, actively maintained package unhealthy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.