The package includes a substantial test suite, a clear README, and release notes for this version. Maintenance recently slowed, and the workflow uses three unpinned actions; the missing security policy is a smaller transparency gap.
78%
Total Score
88
100
94
67
The project has existed for about 5 years and 10 months with 35 releases, but only one release in the last 12 months. The release published today and the short historical median interval partly offset the recent slowdown.
There were no commits and no active maintainers in the last three months. Recent merged pull requests and the release published today provide some compensation, but the direct commit inactivity still weakens maintenance confidence.
The repository has no security policy. For a package handling purchase verification and signed notifications, this is a real disclosure and transparency gap.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. All three action references are unpinned, which leaves the build exposed to reference changes and warrants a minor hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.3 | — | — |
nesbot/carbon Version ^2.66|^3.8 | — | — |
lcobucci/clock Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^8.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.