The package has a clear MIT license, substantial documentation, tests, release notes, and a security policy. Its small project footprint and limited recent activity leave less evidence of sustained maintenance.
68%
Total Score
50
100
88
88
The registry lists one maintainer. Because the repository is user-owned rather than organization-owned, the short publishing base is not compensated by visible organizational backing.
The repository is owned by the same individual as the registry namespace and is not organization-backed. This confirms the concentrated maintainer context rather than adding independent maintenance capacity.
One contributor made 100% of the commits in the last 3 months. This concentration creates a meaningful continuity risk for a package handling subscriptions and payments.
Only 1 commit was recorded in the last 3 months, with 1 active maintainer. That is limited recent activity for billing software and leaves maintenance continuity uncertain.
Composer build tooling is present, but no security scanning tools were detected. The absence of scanning is a hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^10.0 || ^11.0 | — | — |
stripe/stripe-php Version ^13.0 | — | — |
illuminate/console Version ^10.0 || ^11.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 | — | — |
illuminate/database Version ^10.0 || ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.