The package has a clear MIT license, documentation, repository tests, and a small dependency surface. Workflow permissions, unpinned actions, and a high-confidence bot-condition finding add maintenance risk.
46%
Total Score
25
83
50
The package has had no releases in the last 12 months, and its latest release is more than two years old. Only four releases provide limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the prolonged release gap and indicating likely abandonment risk.
There were no new or closed issues or pull requests in the last month, while three pull requests remain open; this suggests limited recent project response.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented for a payment integration package.
All nine action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-condition finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.