Clear documentation, tests, release notes, and a matching source repository support adoption. Two registry maintainers and no published security policy reduce confidence in long-term support.
68%
Total Score
75
100
94
75
The repository recorded zero commits and zero active maintainers in the last three months, despite publishing version 4.0.1 during that period. This leaves a meaningful concern about ongoing maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage weakens repository hygiene for a package handling payments.
No security policy was found in the repository. For a payment-handling package, that reduces transparency around vulnerability reporting and response.
Both workflows were fully analyzed with no dangerous triggers or audit findings, but all 7 action references are unpinned and one workflow grants top-level write permissions. This is a workflow-reproducibility and least-privilege caution, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^11.0|^12.0|^13.0 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/mail Version ^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^3.5 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.