Documentation and tests make integration clearer. There is no security policy, and installation runs a post-autoload-dump script.
68%
Total Score
67
50
88
63
The package declares 11 runtime dependencies, including Laravel, Stripe, and filesystem components. This is a meaningful integration surface and increases dependency maintenance exposure, without being excessive for a finance module.
The package runs a post-autoload-dump install-time script. This adds installation complexity and warrants checking what the script executes, though the signal alone does not show harmful behavior.
One contributor made all 36 recent commits, creating a concentrated maintenance bus factor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded 36 commits in the last 3 months, showing active development. However, all activity came from one maintainer, leaving limited visible redundancy.
Composer build tooling is present, but no security scanning tools were detected. For a finance-related package, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
kompo/auth Version ^0.7.10 | — | — |
kompo/kompo Version * | — | — |
condoedge/eft Version * | — | — |
dedoc/scramble Version ^0.12.19 | — | — |
condoedge/utils Version ^0.2.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.