The package is young and remains pre-1.0, with releases concentrated in its first week and no new registry release for about 16 weeks. Organization backing and a repository pushed within the last week help, but no security policy or scanning is provided.
68%
Total Score
100
100
71
75
Although the package has 35 releases, they were concentrated in about one week and the latest registry release was about 16 weeks ago. Recent repository activity partly offsets the release gap but does not show current published releases.
The repository has zero stars, forks, and watchers, so there is little public adoption evidence. Popularity is supporting evidence rather than a health verdict, and the recent push provides some compensating evidence.
Composer build tooling is present, but no security-scanning tools are reported. That leaves a meaningful transparency and maintenance-safeguard gap for a billing-related package.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. No other provided signal establishes a formal security process.
Version v0.1.34 is not a stable-major release, so the package may still undergo compatibility changes. It is not marked as a prerelease, which provides some stability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aiarmada/cashier Version self.version | — | — |
filament/filament Version ^5.6.5 | — | — |
aiarmada/commerce-support Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.