The package has a long release history, recent activity, tests, and a clear README. Licensing metadata conflicts, and the repository has no security policy or security-scanning tooling.
82%
Total Score
83
100
88
83
The artifact includes license files and the repository has one, but the manifest declares proprietary while the detected artifact license is MIT; that mismatch reduces clarity.
One contributor made 12 of 13 recent commits, but a second contributor remains active and the repository is organization-owned, partly compensating for the concentration.
Composer is used for builds, but no security-scanning tools are reported, leaving a modest verification gap.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
stripe/stripe-php Version ^7.128 | — | — |
blesta/composer-installer Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.