Documentation, repository tests, and release notes are unusually complete for a new package. The small contributor base and workflow configuration leave meaningful maintenance and delivery-process risk.
70%
Total Score
88
100
94
75
This is a young package at 108 days old with three releases and a median interval of about 44 days. The latest release is recent, but the short history provides limited evidence of long-term maintenance.
The repository had four commits from two active maintainers in the last three months, showing ongoing work but a relatively sparse cadence for a young billing package.
The repository has no security policy, leaving vulnerability-reporting expectations and response ownership unclear for a package handling billing integrations.
All 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Three workflows also grant top-level write access, although no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ^3.1 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
barryvdh/laravel-dompdf Version ^3.1 | — | — |
cleaniquecoders/traitify Version ^1.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.