The package is narrowly documented and has no install-time scripts. Its source tree includes an RSA private-key file, so verify that it is not a real deployment credential before adoption.
38%
Total Score
0
75
50
The nine-file artifact is small, but it includes rsa_private_key.pem alongside payment code. Even if intended for examples or testing, shipping a private-key file creates a significant credential-handling concern.
The package has only one release, published about 9 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a payment integration package.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the package's long release hiatus. The repository is not archived, but there is no observed recent maintenance.
The linked repository has 3 stars, 0 forks, and 1 watcher, providing little evidence of independent use or community oversight. Low popularity alone is not disqualifying, but it does not compensate for the lack of maintenance.
The project uses Composer, which is appropriate for the ecosystem, but no security-scanning tools were detected. That leaves the old payment implementation and bundled key material with limited visible security oversight.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.