MIT licensing and one runtime dependency make the package easy to inspect and integrate. Its small repository, single maintainer, and missing security policy limit confidence in ongoing support.
40%
Total Score
25
100
75
83
The package has only 3 releases, all concentrated between April and May 2018, with no release in more than 8 years. That strongly indicates abandonment risk for a payment integration.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months, and its last push was in May 2018. This is strong evidence that maintenance has stopped.
Only one registry maintainer, zqhong, is listed. A single maintainer is not inherently unhealthy for a small package, but it provides little apparent continuity when combined with the lack of recent activity.
The repository has 1 star, 2 forks, and 1 watcher. Low adoption is supporting evidence of a small, lightly supported project, but it is not decisive on its own.
Composer is used for the build, but no security-scanning tooling is present. This is a modest process gap, especially for payment-related code, though it does not by itself show an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
omnipay/common Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.