Its 1,027-file source tree includes tests, and the MIT declaration plus Composer build provide useful structure. The lack of a security policy and security scanning matters for a large package with 26 runtime dependencies.
61%
Total Score
75
50
81
83
The package declares 26 runtime dependencies, including several framework, payment, email, PDF, and media components. That breadth increases upgrade and compatibility surface area, though it is consistent with an e-commerce framework.
The package contains tests and the repository also reports tests, which supports basic project maturity. The missing README and changelog are transparency gaps for a Laravel framework package, though the absence of published tests or changelog files is normal packaging practice.
The package has 119 releases since March 2022, but none in the last 12 months; its latest release was about 20 months ago. The earlier cadence shows maturity, but the prolonged pause lowers confidence in active maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release pause. This is a meaningful maintenance concern despite the package's earlier release history.
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanning layer is a hygiene weakness for a package with many runtime dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdf Version ^1.8 | — | — |
setasign/fpdi Version ^2.3 | — | — |
firebed/sitemap Version dev-master | — | — |
laravel/cashier Version ^12.13 | — | — |
laravel/fortify Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.