The project includes tests, a README, and an MIT declaration, which support basic transparency. The single-maintainer project has no recent activity or security policy, so ongoing support is uncertain.
38%
Total Score
25
79
50
The package has had only 3 releases, all beginning and ending in March 2023, with no releases in the last 12 months. That leaves about 3 years and 6 months without a new release and materially raises abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release gap and indicating no observed ongoing maintenance.
Only one registry account has publish access. The project is user-owned rather than organization-backed, so there is little visible publishing redundancy if that maintainer stops maintaining it.
The repository name does not match the package name and its README does not mention the package, making package-to-source ownership less transparent.
The linked repository has no security policy. For an application exposing web and payment-related code, this is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.8 | — | — |
laravel/sanctum Version ^3.2 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
laravel/framework Version ^10.0 | — | — |
stripe/stripe-php Version ^10.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.