# amzn/amazon-pay-magento-2-module 5.18.5

> Version 5.18.5 of amzn/amazon-pay-magento-2-module, released 2026-08-06.

`composer require amzn/amazon-pay-magento-2-module:5.18.5`

Canonical URL: https://packagento.com/amzn/amazon-pay-magento-2-module/5.18.5

## At a glance

- **Released**: 2026-08-06
- **Magento**: ^102.0||^103.0
- **PHP**: ~7.1.0||~7.2.0||~7.3.0||~7.4.0||~8.0.0||~8.1.0||~8.2.0||~8.3.0||~8.4.0||~8.5.0
- **QA**: failing

## What it does

Official Magento2 Plugin to integrate with Amazon Pay

## Dependencies

### Require

| Package | Constraint |
|---|---|
| amzn/amazon-pay-api-sdk-php | ^2.2 |
| aws/aws-php-sns-message-validator | ^1.5 |
| magento/framework | ^102.0\|\|^103.0 |
| magento/module-backend | ^101.0\|\|^102.0 |
| magento/module-catalog | ^103.0\|\|^104.0 |
| magento/module-checkout | ^100.0 |
| magento/module-config | ^101.0 |
| magento/module-configurable-product | ^100.0 |
| magento/module-customer | ^102.0\|\|^103.0 |
| magento/module-developer | ^100.0 |
| magento/module-directory | ^100.0 |
| magento/module-eav | ^102.0 |
| magento/module-media-storage | ^100.0 |
| magento/module-payment | ^100.0 |
| magento/module-paypal | ^100.0\|\|^101.0 |
| magento/module-quote | ^101.0 |
| magento/module-sales | ^100.0\|\|^101.0\|\|^102.0\|\|^103.0 |
| magento/module-store | ^101.0 |
| magento/module-vault | ^100.1\|\|^101.2 |
| php | ~7.1.0\|\|~7.2.0\|\|~7.3.0\|\|~7.4.0\|\|~8.0.0\|\|~8.1.0\|\|~8.2.0\|\|~8.3.0\|\|~8.4.0\|\|~8.5.0 |
| phpseclib/phpseclib | ~2.0\|\|~3.0 |

### Require (dev)

| Package | Constraint |
|---|---|
| guzzlehttp/guzzle | ^6.2.0 |

### Replace

| Package | Constraint |
|---|---|
| amzn/amazon-pay-and-login-magento-2-module | * |
| amzn/amazon-pay-and-login-with-amazon-core-module | * |
| amzn/amazon-pay-module | * |
| amzn/amazon-pay-v2-magento-2-module | * |
| amzn/amazon-payments-magento-2-plugin | * |
| amzn/login-with-amazon-module | * |

## Quality

Version 5.18.5 fails the Packagento QA pipeline. Verdicts below are per-cell (Magento line × PHP version) for the matrixed tools, and run-once for the static / security tiers.


### Compatibility

Each Magento line is installed on its supported PHP versions, then the module is built (DI compile + static-content deploy). Cells show passed / failed / untested; staircase gaps render as `–`.

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | Pass | Pass | – | – |
| 2.4.8 | – | Pass | Pass | – |
| 2.4.9 | – | – | Pass | Pass |


### Code Quality

Advisory checks against the module's source. Never affect the Compatibility verdict — a phpcs finding can't make a module incompatible.

#### Static Analysis

Coding standards (phpcs), mess detection (phpmd), copy-pasted code (cpd), PHP cross-version compatibility, composer.json validity. Each runs once for the whole module.

| Tool | Status | Findings | Summary |
|---|---|---|---|
| PHPCS | Warning | 2 | 2 warnings (ruleset: Magento2) |
| PHPMD | Warning | 366 | 366 rule violations (UnusedPrivateField:362, ExcessiveClassLength:2, TooManyFields:2) |
| Cpd | Pass | 0 |  |
| Composer validate | Info | 1 | valid; 1 advisory note (composer validate --strict) |

#### PHPStan

Type-checks the module against a real Magento install. Re-runs per Magento + PHP version because resolvable symbols differ between releases.

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | 324 | 324 | – | – |
| 2.4.8 | – | 327 | 327 | – |
| 2.4.9 | – | – | 325 | 325 |


### Tests

Unit and integration suites run per Magento + PHP cell. Test failures speak to the module's behaviour, not its compatibility with a line, so they're reported here separately.

#### Unit Tests

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | N/A | N/A | – | – |
| 2.4.8 | – | N/A | N/A | – |
| 2.4.9 | – | – | N/A | N/A |

#### Integration Tests

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | N/A | N/A | – | – |
| 2.4.8 | – | N/A | N/A | – |
| 2.4.9 | – | – | N/A | N/A |


### Security

Dependency-advisory audit (composer audit) plus a source malware scan. A malware detection fails the version outright.

| Tool | Status | Findings | Summary |
|---|---|---|---|
| Composer audit | N/A | 0 | no resolvable dependency tree to audit: Your requirements could not be resolved to an installable set of packages. Problem 1 |
| Malware scan | Pass | 0 |  |

## Parent package

[amzn/amazon-pay-magento-2-module](https://packagento.com/amzn/amazon-pay-magento-2-module.md) — full catalogue, pricing, install steps, and vendor info.

