Stripe and Stripe Connect for your Laravel App
72%
Total Score
88
100
100
67
A post-autoload-dump install script is present. This is a mild supply-chain consideration, but the provided signal does not show that it performs unsafe actions.
All four recent commits came from one contributor, leaving maintenance highly concentrated. Organization backing partially compensates because work can potentially be handed off.
No security policy was found in the repository, reducing transparency for reporting vulnerabilities in a package that handles Stripe integrations.
All four workflows were analyzed, but all eight action references are unpinned. One workflow also has a high-confidence bot-conditions finding and top-level write permissions; no untrusted checkout or script-injection sink was reported, limiting the impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stripe/stripe-php Version ^16.0||^17.0||^18.0||^19.0||^20.0||^21.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
spatie/laravel-stripe-webhooks Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.