The package includes a clear MIT license, README, tests, and no install-time scripts. It lacks a security policy, and both workflow actions are unpinned, which weakens maintenance and build hygiene.
55%
Total Score
0
70
50
The latest registry release was more than 3 years ago, with no releases in the last 12 months; this is a substantial abandonment concern despite nine releases overall.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the lack of current maintenance activity.
The repository has zero stars, two forks, and one watcher. This is weak supporting evidence for maturity, though popularity alone does not determine health.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented for a payment integration package.
The workflow audit completed cleanly with no dangerous triggers, sinks, or findings, but both analyzed action references are unpinned, leaving avoidable build-supply-chain variability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.2 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
web-token/jwt-core Version 2.2.10 | — | — |
laravelcollective/html Version ^6.2 | — | — |
web-token/jwt-key-mgmt Version 2.2.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.