The package is clearly documented and includes a release note for this version. Repository tests, a matching license, security policy, dependency scanning, and pinned workflow actions provide useful safeguards.
68%
Total Score
70
100
93
83
The package uses a post-autoload-dump Composer lifecycle script. This is a supply-chain surface that merits some caution, although no dangerous behavior is shown by this signal alone.
Only one account has registry publish access. The linked repository is also user-owned, so there is no organization backing shown to offset the limited publishing base, though registry access alone does not establish actual maintenance capacity.
The registry namespace and repository both belong to the same user account, and no organization backing is shown; this is consistent ownership but does not reduce the single-maintainer continuity risk.
All 16 recent commits came from one contributor, creating a meaningful continuity risk for a user-owned project without demonstrated organizational handoff.
v0.3.0 is not a stable-major release, so API compatibility may still change before 1.0. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
codearachnid/check-commerce-php-sdk Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.