It includes a clear README, release notes, repository tests, and a source tree that matches the package. Pin this version cautiously while maintenance resumes and CI permissions and dependency pinning are tightened.
58%
Total Score
50
100
94
75
The repository is owned by an individual user rather than an organization, so the single registry maintainer does not have organizational backing to compensate for the recent lack of commit activity.
There were zero commits and zero active maintainers in the last 3 months. Recent publishing and the June repository push partly offset this, but the current maintenance pause is a meaningful abandonment concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that handles payment integrations.
Version 1.2.1 is a stable, non-prerelease major version, but 64.7% of recent releases were prereleases, which adds some release-process uncertainty.
All 12 analyzed action references are unpinned, and three workflows grant top-level write access. The audit also found one high-confidence bot-conditions issue in the Dependabot auto-merge workflow; no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dnetix/redirection Version ^2.1 | — | — |
illuminate/contracts Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
transbank/transbank-sdk Version ^3.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.