activemerchant/active_merchant
61.8
Adequate · 26 September 2026
72.5k
lines of production code
Ruby
primary language
4
measurements over time
What this system is
This release delivers a significant security upgrade by fixing [CVE redacted] in the rexml gem, alongside a major architectural shift that extracts offsite payment integrations into a separate gem. The core library introduces structured result objects for AVS and CVV checks, modernizes HTTP connection handling with proxy and SSL/TLS configuration support, and adds country code validation. A wide range of payment gateways, including Braintree, PayPal, and Payflow, receive extensive updates, new features like 3D Secure 2 and network tokenization, and refactored internal logic. The release also removes legacy generator scripts, deprecated integrations, and outdated test coverage, while adding comprehensive unit and schema validation tests for the remaining gateways.
Features
Add Cecabank payment gateway support
Introduces the Cecabank payment gateway, enabling merchants to process credit card transactions via both XML and JSON REST APIs. The implementation includes support for standard purchase, authorization, capture, void, and refund operations, along with encrypted sensitive data handling and scrubbing for security compliance.
_lib/active\merchant/billing/gateways/cecabank · high confidence
Add FirstPay gateway support for REST/JSON and digital wallets
Added a new REST/JSON-based implementation of the FirstPay payment gateway (FirstPayJsonGateway) alongside the existing XML-based implementation (FirstPayXmlGateway). The new implementation enables support for Apple Pay and Google Pay via the WALLET\_TYPES mapping and handles network tokenization credit cards. Both implementations share common configuration in a new FirstPayCommon module.
_lib/active\_merchant/billing/gateways/first\pay · high confidence
Add MiGS payment gateway integration
Users can now process payments through the MiGS (Merchant Internet Gateway System) payment provider. This change introduces the necessary mapping codes for transaction responses, issuer responses, and 3D Secure verification statuses, along with credit card type definitions required for the new gateway.
_lib/active\merchant/billing/gateways/migs · high confidence
Add QuickPay V10 API support with shared common logic
The QuickPay gateway now supports the V10 API alongside existing V4-V7 implementations. A new \QuickpayCommon\ module provides shared configuration, including supported countries, card types, and response codes, while \QuickpayV10\ implements the new API version with features like customer IP tracking, 3D Secure parameters, and synchronous operations. The V4-V7 gateway continues to support older API versions with XML-based communication.
_lib/active\merchant/billing/gateways/quickpay · high confidence
Added support scripts for gateway inspection and SSL verification
New Ruby scripts in lib/support enable programmatic inspection of payment gateways and verification of their SSL/TLS configurations. GatewaySupport enumerates all available gateways and their supported actions, while OutboundHosts scans the codebase to list external hosts contacted by gateways. SSLVerify checks that each gateway's live URL presents a valid SSL certificate, and SSLVersion tests whether each gateway supports a minimum TLS version (defaulting to TLS 1.1). These tools provide a way to audit gateway capabilities and security posture directly from the codebase.
lib/support · high confidence
Introduces structured result objects for AVS and CVV checks
The library now uses dedicated \AVSResult\ and \CVVResult\ classes to represent Address Verification System and Card Verification Value check outcomes. These objects encapsulate the raw response codes and human-readable messages, and are exposed via the \Response\ object's \avs\_result\ and \cvv\_result\ attributes. This change replaces the previous approach of returning raw strings or hashes, providing a more robust and consistent way to inspect verification statuses.
_lib/active\merchant/billing · high confidence
Refactored HTTP connection handling and added country code support
The library has been refactored to use a new, dedicated \Connection\ class for managing HTTP/HTTPS requests, introducing support for proxy configuration (address, port, user, password) and configurable SSL/TLS versions (min/max). Additionally, a new \Country\ class has been added to provide structured access to ISO 3166-1 country codes (alpha2, alpha3, and numeric), enabling more robust country validation and formatting in payment flows.
_lib/active\merchant · high confidence
Removals
Nochex integration removed from ActiveMerchant
The Nochex payment integration, including its helper and notification classes, has been removed from the ActiveMerchant library. This change eliminates the ability to process payments via the Nochex gateway.
_lib/active\merchant/billing/integrations/nochex · high confidence
Removal of PayPal integration helper and notification classes
The PayPal integration helper and notification classes have been removed from the codebase. This eliminates the built-in support for handling PayPal IPN (Instant Payment Notification) webhooks and generating the necessary form fields for PayPal checkout flows. Users relying on these specific integration classes will need to migrate to alternative payment processing methods.
_lib/active\merchant/billing/integrations/paypal · high confidence
Removed Chronopay integration files
The Chronopay integration helper and notification classes have been removed from the ActiveMerchant billing module. This eliminates the ability to process payments and handle notifications for the Chronopay gateway.
_lib/active\merchant/billing/integrations/chronopay · high confidence
Removed Gestpay integration implementation files
The Gestpay integration files (common.rb, helper.rb, notification.rb) have been deleted from the codebase. This removes the ability to process payments and notifications via the Gestpay payment gateway.
_lib/active\merchant/billing/integrations/gestpay · high confidence
Removed gateway generator templates and scaffolding
The generator templates for creating new payment gateways (including the Ruby generator class and associated template files for unit and remote tests) have been removed from the codebase. This eliminates the automated scaffolding tool used to generate new gateway implementations, meaning developers must now create new gateways manually or via other means.
script/generator/generators/gateway · high confidence
Removed legacy script/generator scripts
The legacy generator scripts in the script/generator directory (base.rb, generator.rb, and manifest.rb) have been removed. This eliminates the 'script/generate' command-line tool used for generating payment gateways and integrations, indicating a shift away from this code generation workflow.
script/generator · high confidence
Removed offsite payment integrations from the main library
The \lib/active\_merchant/billing/integrations\ directory has been removed, deleting the \ActionViewHelper\ and all individual integration modules (such as PayPal, Nochex, and others). This change extracts the offsite payment integrations into a separate \offsite\_payments\ gem, meaning users must now depend on that external gem to use these features.
_lib/active\merchant/billing/integrations · high confidence
Removed the CIA build notification rake task
The Rake task responsible for monitoring the Subversion repository and sending email notifications about build failures has been removed. This eliminates the automatic email alerts for broken builds.
lib/tasks · high confidence
Security
Upgrade rexml to 3.3.8 to fix [CVE redacted]
The rexml gem has been upgraded to version 3.3.8 to address the security vulnerability [CVE redacted], ensuring the library is protected against the identified XML processing issue.
(repo-wide) · high confidence
Behavioural changes
Add Gemfiles for testing against multiple Rails and ActiveSupport versions
The project now includes dedicated Gemfiles for testing compatibility with specific versions of the Rails framework and the ActiveSupport library. New files have been added to the gemfiles directory to pin activesupport versions 4.2.0, 5.0.0, 5.1.0, 5.2.0, 6.0.0, and 7.2.1, each evaluating the main Gemfile to ensure the library functions correctly across these different environments.
gemfiles · medium confidence
Added support for additional currencies and soft descriptors in the Orbital gateway
The Orbital gateway now supports a significantly expanded list of currencies, with new ISO codes and their corresponding numeric codes added to \orbital\_codes.rb\. Additionally, a new \OrbitalSoftDescriptors\ class has been introduced to handle merchant name, city, phone, URL, and email for Chase Paymentech Canada customers, including validation for phone number formats and field length limits.
_lib/active\merchant/billing/gateways/orbital · high confidence
Braintree gateway refactored with shared common logic and new token nonce implementation
The Braintree gateway implementation has been restructured to extract shared configuration and scrubbing logic into a new \BraintreeCommon\ module, which defines supported countries, card types (including Diners Club and Maestro), and sensitive data filtering rules. Additionally, a new \TokenNonce\ class has been introduced to handle the creation of credit card and bank account (ACH) nonces via Braintree's GraphQL API, supporting both credit card and ACH payment methods with proper address and mandate handling.
_lib/active\merchant/billing/gateways/braintree · high confidence
Extensive updates to payment gateway implementations
This change introduces a wide range of updates across multiple payment gateways, including the addition of new gateways (e.g., HiPay, Global Transport, Rapyd, and others), support for new features such as 3D Secure 2, network tokenization, and Apple/Google Pay, as well as numerous bug fixes, deprecations, and API version updates. Specific gateways like Adyen, Worldpay, CyberSource, and Stripe have received significant updates to their functionality and supported fields.
_lib/active\merchant/billing/gateways · high confidence
Introduce Thor-based gateway generator
The gateway generator has been rewritten to use Thor instead of the previous Rubigen-based implementation. This change updates the generator's internal structure and templates, ensuring that newly generated gateways include a verify method, error code handling, and transcript scrubbing support.
generators · high confidence
Introduce recurring payments and EFT/ACH support for Beanstream
The Beanstream gateway now supports recurring payments, allowing users to set up and manage subscription-based transactions. Additionally, the gateway adds support for EFT/ACH and Interac Online payments, expanding the range of payment methods available to users. The implementation includes mapping ISO province codes for US and CA, sending customer IP for fraud management, and handling secure profiles.
_lib/active\merchant/billing/gateways/beanstream · high confidence
Modernizes ActiveMerchant's core loading and deprecation handling
ActiveMerchant now explicitly requires specific ActiveSupport extensions and standard library modules (such as base64, securerandom, and timeout) rather than relying on implicit or gem-based loading. The library also introduces a centralized deprecation warning system that logs messages via a logger or standard output, and enforces I18n locale availability.
lib · high confidence
PayPal: Deprecate recurring billing and add new API capabilities
The PayPal gateway has deprecated the recurring billing functionality (recurring, update\_recurring, cancel\_recurring, etc.), which will now emit deprecation warnings. The gateway also adds support for new PayPal API features, including mass payments (transfer), full and partial refunds, reauthorization, and the GetTransactionDetails/GetBalance/DoAuthorization/ManagePendingTransactionStatus/RequestDetails wrapping. Additionally, the response object now exposes the checkout status, contact phone number, and note field, while the common API now supports API signatures and updated API versions.
_lib/active\merchant/billing/gateways/paypal · high confidence
Payflow gateway refactored to support NVP and recurring billing
The Payflow gateway implementation was refactored to support the PayPal NVP protocol, enabling safe retries for connection failures and allowing separate vendor and user credentials. A new PayflowResponse class was introduced to expose the profile ID and payment history, while the PayflowExpressResponse was updated to include phone number, full name, and shipping address details. The change also adds support for recurring billing transactions and introduces a verbosity option for requests.
_lib/active\merchant/billing/gateways/payflow · high confidence
Refactored script/generate to use Thor instead of Rubigen
The script/generate command-line tool has been rewritten to use the Thor library instead of the previous Rubigen-based implementation. This change updates the underlying framework for generating code (such as new gateways), which may affect how the script is invoked or how generators are loaded, but provides a more modern and consistent command-line interface.
script · high confidence
Removal of integration generator templates
The integration generator templates (including helper, notification, and module test templates) have been removed from the project. This change eliminates the scaffolding used to generate integration payment processor templates, indicating a shift away from this code generation approach.
script/generator/generators/integration · high confidence
Removed example reference file
The example reference file tc\_example.rb, which demonstrated usage of the ActiveMerchant library for Trust Commerce, has been removed from the references directory.
references · high confidence
Removed legacy ActiveMerchant modules
Deleted the Country, PostsData, RequiresParameters, and Validateable modules from lib/active\_merchant/lib. This removes the country code validation, the low-level HTTP POST helper, the parameter validation helper, and the validation/error-handling mixin that previously supported credit card and other gateway objects.
_lib/active\merchant/lib · high confidence
Updated root certificate bundle
The \lib/certs/cacert.pem\ file has been updated to include additional root certificates, specifically adding support for DigiCert, Wirecard, Barclays, and other authorities to improve SSL/TLS verification for gateways using \ssl\_post\.
lib/certs · medium confidence
Test coverage
Add unit tests for gateways in test/unit/gateways; Added CyberSource XSD schema validation files for versions 1.121, 1.153, 1.155, 1.156, and 1.164; Added PayPal XSD schema files for XML validation; Added XSD schema files for Orbital request types PTI77, PTI83, and PTI95; Added XSD schemas for FirstData E4 gateway versions 11 and 27; Added unit tests for PayPal gateway common API; Added unit tests for core payment and connection components; Expanded remote test coverage across numerous payment gateways; Modernize test infrastructure with new stubbing and assertion helpers; Removed integration helper tests for Bogus, Chronopay, Gestpay, Nochex, and PayPal; Removed integration notification tests for Chronopay, Gestpay, Nochex, PayPal, and the base Notification class; Removed obsolete integration tests; Removed remote tests for multiple payment gateways.
Dependencies
Modernize Ruby and dependency configuration
The project now requires Ruby 3.1 or higher and enforces pessimistic versioning on core dependencies like activesupport (\>= 4.2), builder, i18n, nokogiri, and rexml. A new Gemfile explicitly lists optional test and remote-test dependencies (such as braintree, concurrent-ruby, and mocha) to keep them out of the main gemspec, while development dependencies like pry and test-unit are also explicitly declared.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 32 → 62 (+29.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 92 → 82 (-10.6)
- Architecture 94 → 66 (-28.4)
- Maturity 61 → 55 (-5.5)
- Readiness 27 → 67 (+40.0)
- Security 11 → 68 (+57.8)
Resolved (33)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (lib/active_merchant/billing/gateways/mit.rb)
- Duplicated block (10 lines × 2) (lib/active_merchant/billing/gateways/netbanx.rb)
- Duplicated block (10 lines × 4) (lib/active_merchant/billing/gateways/authorize_net_cim.rb)
- Duplicated block (5 lines × 2) (lib/active_merchant/billing/gateways/jetpay.rb)
- Duplicated block (6 lines × 2) (lib/active_merchant/billing/gateways/jetpay_v2.rb)
- Duplicated block (6 lines × 2) (lib/active_merchant/billing/gateways/payu_latam.rb)
- Duplicated block (7 lines × 2) (lib/active_merchant/billing/gateways/itransact.rb)
- Duplicated block (7 lines × 2) (lib/active_merchant/billing/gateways/mastercard.rb)
- Duplicated block (8 lines × 2) (lib/active_merchant/billing/gateways/global_collect.rb)
- Duplicated block (8 lines × 2) (lib/active_merchant/billing/gateways/simetrik.rb)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 13 more
New (468)
- AdyenGateway.add_3ds (cognitive 18) (lib/active_merchant/billing/gateways/adyen.rb)
- AdyenGateway.add_extra_data (cognitive 16) (lib/active_merchant/billing/gateways/adyen.rb)
- AdyenGateway.add_extra_data (cyclomatic 17) (lib/active_merchant/billing/gateways/adyen.rb)
- AuthorizeNetCimGateway.add_transaction (cognitive 20) (lib/active_merchant/billing/gateways/authorize_net_cim.rb)
- AuthorizeNetGateway.parse_cim (cognitive 20) (lib/active_merchant/billing/gateways/authorize_net.rb)
- AuthorizeNetGateway.parse_normal (cognitive 34) (lib/active_merchant/billing/gateways/authorize_net.rb)
- AuthorizeNetGateway.parse_normal (cyclomatic 24) (lib/active_merchant/billing/gateways/authorize_net.rb)
- BraintreeBlueGateway.verify (cognitive 18) (lib/active_merchant/billing/gateways/braintree_blue.rb)
- CardConnectGateway.add_address (cognitive 16) (lib/active_merchant/billing/gateways/card_connect.rb)
- CheckoutV2Gateway.add_3ds (cognitive 20) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_customer_data (cognitive 16) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_payment_method (cognitive 44) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_payment_method (cyclomatic 21) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_payment_sender_data (cognitive 30) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_payment_sender_data (cyclomatic 22) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_payout_destination_data (cognitive 25) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_payout_destination_data (cyclomatic 20) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_recipient_data (cognitive 21) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- CheckoutV2Gateway.add_recipient_data (cyclomatic 16) (lib/active_merchant/billing/gateways/checkout_v2.rb)
- ConektaGateway.add_address (cognitive 16) (lib/active_merchant/billing/gateways/conekta.rb)
- …and 448 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
activemerchant/active_merchant was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ca45b1b063ce2e1495e1427e0a1d42dcb482d57d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.