The repository has no recent commits, no security policy, and no meaningful adoption activity. The package is documented as deprecated, so new integrations should use PayPal’s direct REST API instead.
35%
Total Score
0
56
75
The package includes a substantial README and tests, but the README explicitly says the SDK is deprecated and will receive no new features or support. That materially outweighs the otherwise useful documentation and test coverage.
The package has had four releases, but its latest release was over three years ago and there were no releases in the last 12 months. This indicates a stalled release lifecycle for an integration SDK.
The repository recorded zero commits and zero active maintainers in the last three months. The linked repository is not archived, but that does not compensate for the observed lack of maintenance.
The linked repository name does not match the package name and its README does not mention this package. That makes package-to-repository ownership less transparent and adds adoption risk.
The project uses Composer, which supports reproducible package development, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xcode75/paypalhttp Version 1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.