Risky to adopt without taking ownership: the package has had no release since November 2018 and no repository activity in the last three months. It is licensed, documented, tested, and not deprecated or archived, but its long-term maintenance appears abandoned.
45%
Total Score
0
100
75
75
Only one release exists, from November 2018, with no releases in the last 12 months. A package with roughly seven years since its last release has a substantial maintenance and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long period without a release. This is strong evidence that ongoing maintenance is absent.
The repository has zero stars, one fork, and one watcher, indicating little visible adoption or community support. Popularity is only supporting evidence, but it provides no compensating maintenance signal here.
The repository has no published security policy. This is a transparency gap, although it is less significant than the package's demonstrated long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kabangi/mpesa Version ^3.0 | — | — |
omnipay/common Version ^3.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.