It includes a clear license, substantial README, comprehensive tests, and no install-time scripts. The repository has had no commits or releases since December 2021, lacks security tooling and policy, and uses six unpinned workflow actions.
56%
Total Score
50
50
83
83
Six runtime dependencies create a meaningful maintenance surface for a receipt-validation library, though the profile is not unusually large or inherently unsafe.
The package has 40 releases since March 2019 but none in the last 12 months; its latest release was in December 2021, indicating prolonged release inactivity.
There were no commits and no active maintainers in the past three months, consistent with the last repository push in December 2021 and raising abandonment risk.
The repository has zero stars, forks, and watchers, providing no adoption signal to offset the inactive maintenance record; popularity is supporting evidence rather than a verdict.
Composer build tooling is present, but no security-scanning tools were detected, leaving dependency and code-security checks less visible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.0|^2.0 | — | — |
google/apiclient Version ^2.10 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
robrichards/xmlseclibs Version ^3.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.