The package is MIT-licensed, has a substantial README, and has no install-time scripts. Its repository shows no commits or active maintainers in three months, while the release workflow uses broad permissions and unpinned actions.
61%
Total Score
50
100
89
67
The repository is owned by an individual account rather than an organization, so the two-account registry maintainer list provides limited evidence of durable project backing.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful maintenance concern that conflicts with the recent registry release cadence.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no external adoption signal to offset the thin maintenance evidence.
Composer is used for builds, but no security-scanning tooling is detected, leaving a modest transparency and maintenance gap for a package handling payment integrations.
The repository has no security policy, reducing the clarity of vulnerability reporting and maintainer response expectations for a payment-related SDK.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.