The package is well documented and tested, with only two runtime dependencies and no install-time scripts. Its repository is not archived, but registry releases stopped about 4 years and 6 months ago, recent commits are absent, and workflow references are unpinned.
60%
Total Score
50
100
88
67
The package has 10 releases since December 2016, but its latest registry release was about 4 years and 6 months ago and it had no releases in the last 12 months. That materially raises maintenance and compatibility risk.
There were zero commits and zero active maintainers in the last 3 months. Combined with the old registry release, this indicates limited current maintenance capacity.
The repository uses Composer, showing basic build tooling, but no security scanning tools were detected. For this small package this is a minor transparency gap, not a severe risk.
No repository security policy was found. This is a modest disclosure and maintenance gap, though the package is a small test-token utility rather than a security-sensitive service.
The only workflow was fully analyzed with no reported audit findings and no dangerous triggers or untrusted checkouts. However, both of its two action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stripe/stripe-php Version ^4.0|^5.0|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.