The repository includes tests, a clear README, a license, and a simple Composer dependency profile. The project is not archived, but its maintenance and workflow hygiene warrant checking before adoption.
58%
Total Score
75
100
81
83
The latest release was published about 6 years and 8 months ago, with no releases in the last 12 months. This materially raises abandonment and compatibility risk despite the package's established history of 8 releases.
There were no commits and no active maintainers in the last 3 months. Combined with the old latest release, this indicates weak current maintenance activity.
The project uses Composer, but no security-scanning tools were detected. This is a modest transparency and maintenance-process gap, not evidence of unsafe code.
No repository security policy was found. For a payment-processing extension, the absence of documented vulnerability-reporting guidance is a meaningful transparency gap.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, all 5 action references are unpinned, leaving avoidable build reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ~2.0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.