The small dependency surface and tested, documented package reduce integration risk. A clear license, release notes, and organization-backed repository improve transparency, but ongoing support cannot be assumed.
58%
Total Score
67
100
88
75
The package has seven releases over roughly 12 years, but none in the last six years; the long release interval and complete recent inactivity indicate a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's prolonged lack of releases and raising abandonment risk.
There were no new or closed issues or pull requests in the last month, with one issue still open; this provides no evidence of current support.
The project uses Make and Composer, showing basic build structure, but no security-scanning tooling is present, which is a minor hygiene gap for a payment library.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; the package's payment integration context makes this a genuine transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.