
Security News
Follow-up and Clarification on Recent Malicious Ruby Gems Campaign
A clarification on our recent research investigating 60 malicious Ruby gems.
@lorenstuff/paypal-api
Advanced tools
Supply Chain Security
Vulnerability
Quality
Maintenance
License
Unpopular package
QualityThis package is not very popular.
Found 1 instance in 1 package
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
A class for interacting with the PayPal API.
I made this package because PayPal does not provide a complete solution for doing this and their docs are sorely lacking in quality.
Note: This package is in alpha and there may be breaking changes before Major Version 1.0. If you do decide to use it, I suggest you pin your dependency at a specific version and carefully investigate changelogs.
Install the package with NPM:
npm install @lorenstuff/paypal-api
To use the package, simply import the PayPal
class and create an instance of it with your PayPal Client ID and Secret. You will also need to specify whether the credentials are for sandbox mode or live mode:
import { PayPal } from "@lorenstuff/paypal-api";
const paypal = new PayPal(
{
sandbox: true,
clientId: "YOUR_CLIENT_ID_HERE",
secret: "YOUR_SECRET_HERE",
});
Once you have an instance of the class, you can call various methods on it such as createOrder
to interact with the API. There are exhaustive types included as part of this module to help you know what to put.
Also, this is by no means a complete library at the moment and it may be quite some time before it is. That said, I still hope it helps.
More detailed documentation will be coming at a later date.
See CHANGELOG.md
0.1.6
Adding "type": "module"
to package.json.
FAQs
A library for interacting with PayPal's API.
The npm package @lorenstuff/paypal-api receives a total of 1 weekly downloads. As such, @lorenstuff/paypal-api popularity was classified as not popular.
We found that @lorenstuff/paypal-api demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
A clarification on our recent research investigating 60 malicious Ruby gems.
Security News
ESLint now supports parallel linting with a new --concurrency flag, delivering major speed gains and closing a 10-year-old feature request.
Research
/Security News
A malicious Go module posing as an SSH brute forcer exfiltrates stolen credentials to a Telegram bot controlled by a Russian-speaking threat actor.