The organization-backed project has clear release documentation, tests, and a recent published update. Maintenance is concentrated in one contributor, and CI action references are all unpinned; there is also no security policy.
70%
Total Score
75
100
93
75
All three commits in the last three months came from one contributor, giving the project a bus factor of one during the observed period. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The project uses Make and Composer, but no security-scanning tools were detected. For a payment integration library, that is a modest maintenance and transparency gap.
The repository has no security policy. This does not show a security defect, but it leaves vulnerability-reporting expectations undocumented for a package handling payment integrations.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or write-wide token permissions. However, all 6 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
payum/core Version ^1.7 | — | — |
php-http/message-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.