The MIT declaration and setup documentation help consumers get started, but the payment code shows little evidence of ongoing review or maintenance. The small project also lacks a security process and includes a private-key file in its published tree, increasing reliance risk.
40%
Total Score
0
79
67
This package has only one release, published 9 years ago, with no releases in the last 12 months. That strongly suggests abandonment risk for a payment integration.
The repository recorded no commits or active maintainers in the last 3 months, and its last push was in March 2020. The non-archived status does not compensate for this prolonged inactivity.
The nine-file package tree includes rsa_private_key.pem alongside payment code. Even without inspecting its contents, publishing a private-key-named file is a serious transparency and operational concern.
The repository has only 3 stars, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little evidence of broad review or community support.
The linked repository has no security policy or documented security reporting process. That is a meaningful gap for a package handling payment credentials and signatures.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.