The package has clear usage documentation, tests in the repository, and a source tree that matches the package. Its single-person ownership, sparse release history, and lack of recent commits make long-term maintenance less certain.
65%
Total Score
50
100
88
75
Only one registry account has publish access, and project backing identifies an individual owner rather than an organization. This leaves limited visible maintainer redundancy if that person stops supporting the project.
The package has existed for about 5 years and 10 months, but only 5 releases overall, with 1 release in the last year and a median interval of about 20 months. This indicates a slow maintenance cadence, though the release in the last year is evidence the project is not abandoned.
The repository recorded 0 commits and 0 active maintainers in the past 3 months. The recent release and repository push partly offset this, but the current development pace is still quiet.
Composer build tooling is present, but no security scanning tools were detected. For a payment QR-code library, that is a modest transparency and maintenance gap, not evidence of unsafe behavior by itself.
The repository has no security policy. That reduces clarity about how vulnerabilities should be reported and handled, especially for a package involved in payment workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
f9webltd/simple-qrcode Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.