Compatibility and long-term support remain uncertain for this young v0.x package. Tests, licensing, and security scanning are reassuring, but the stalled repository and unpinned workflow actions add maintenance and build-reproducibility risk.
55%
Total Score
0
83
50
There were zero commits and zero active maintainers in the last three months, following a last push about 10 months ago. For a payment package, this is a meaningful sign of stalled maintenance.
The package is 320 days old with five releases, but all five arrived within roughly four days and none followed during the remaining period. That burst does not demonstrate sustained maintenance.
No security policy is present. That is a transparency gap for a package handling payment and billing flows, even though GitGuardian scanning provides partial compensation.
The latest version is v0.4 and is not a stable major release, so compatibility and API maturity remain less certain for a Laravel billing integration.
The single workflow was fully analyzed with no injection or high-severity findings, but both of its action references are unpinned. This leaves builds exposed to moving action revisions and is a moderate reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/ray Version * | — | — |
moneyphp/money Version * | — | — |
symfony/dotenv Version * | — | — |
guzzlehttp/psr7 Version * | — | — |
guzzlehttp/guzzle Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.