The package is young and integrates many payment providers through 15 runtime dependencies. A security policy and automated security scanning are absent, while organization backing, tests, documentation, and a recent release provide useful support.
62%
Total Score
67
50
86
75
The package declares 15 runtime dependencies, including many payment-provider SDKs. That broad dependency surface increases update and compatibility exposure for consumers.
This is a young package, about 173 days old, with six releases in the last 12 months and a median interval of about 19 hours. The frequent releases show activity but leave limited long-term maintenance history.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning for a payment integration package.
Two issues were opened in the last month and none were closed, leaving three open issues overall. This suggests unresolved maintenance work, though the short project history limits how strongly it should be weighed.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning reduces supply-chain and code-quality transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
square/square Version 37.1.0.20240604 | — | — |
srmklive/paypal Version ~3.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
laravel/framework Version ^12.13.0 | — | — |
razorpay/razorpay Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.