Clear documentation and a tested source tree make integration easier. The short release history and missing security safeguards leave limited evidence of long-term support.
79%
Total Score
100
100
83
67
The package runs a post-autoload-dump install-time script. This is not inherently unsafe, but it adds installation behavior that should be understood before adoption.
The package is only 86 days old and has two releases, both published within minutes on the first day, so long-term maintenance is not yet demonstrated.
The repository has one star and no forks, so there is little external adoption evidence. For a young, focused package this is supporting evidence only, not a health verdict.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest gap in repository transparency and ongoing checks.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less clear for a package handling webhook signatures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.