This is a usable but immature package with good baseline transparency: it is MIT-licensed, has a substantial README, source-repository tests, a coherent file tree, no install-time lifecycle scripts, and is neither deprecated nor archived. However, it is only 122 days old, its nine releases have arrived at a very rapid cadence, and the repository records zero commits and zero active maintainers over the last three months, leaving maintenance continuity unproven despite the recent release. The zero-star, single-user-owned repository, absence of security scanning and a security policy, and lack of workflow automation add moderate confidence and operational concerns. It may be reasonable for evaluation or controlled use, but a payment package should be adopted with close review and a fallback plan.
62%
Total Score
50
100
83
90
The repository is owned by a user rather than an organization, so the available ownership evidence indicates a potentially thin project backing for a young payment package.
The package is very young at 122 days and has nine releases, with a median interval of about 1 hour; this shows release activity but also an unusually compressed history that provides little evidence of long-term stability.
The repository reports zero commits and zero active maintainers in the last three months. That conflicts with the recent registry release and leaves ongoing maintenance capacity unproven, which is material for a payment dependency.
The repository has zero stars, forks, and watchers. Popularity is not required for health, but this provides no external adoption evidence for a young package.
Composer build tooling is present, but no security scanning tools are configured; the missing scanning is a maintenance and transparency gap for payment-related code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.