The package is clearly documented, tested, licensed, and has no install-time scripts. Its single release, minimal repository activity, absent security policy, and unpinned workflow actions leave meaningful maintenance and build-transparency concerns.
68%
Total Score
50
100
78
67
The repository owner is an individual user rather than an organization, so the single registry maintainer does not have organizational backing to compensate for the thin maintenance evidence.
Only one release has been published, with the latest release occurring 362 days after the package first appeared; this provides little evidence of sustained maintenance.
There are no open issues or pull requests and no issue or pull-request activity in the last month; this is neutral for a small project but does not demonstrate active support.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these very low counters provide little external validation.
Composer build tooling is present, but no security scanning tools are reported, leaving a transparency gap for a package handling payment integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.