It has a substantial README, tests, an MIT declaration, and no install-time scripts. Organization backing and active recent work help, but workflow references are unpinned and security practices are undocumented.
67%
Total Score
83
100
79
67
The package is less than one day old, with three releases published within minutes, so its maintenance history and production maturity are not yet established.
All 15 recent commits came from one contributor, creating a real continuity risk; organization ownership provides some capacity to hand off maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving security-process maturity unverified for a package handling billing and payment integrations.
The repository has no security policy, which reduces transparency about vulnerability reporting and response expectations for payment-related code.
Version v1.0.2 is a stable major release and not a prerelease, which is positive, but the release line has no meaningful history yet.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
guzzlehttp/guzzle Version ^7.0 || ^8.0 | — | — |
stripe/stripe-php Version ^20.1 | — | — |
ceibacore/ceiba-db Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.