The package is MIT-licensed, matches its repository, and has tests plus release notes for this version. A single-person project with no security policy and weak workflow pinning has less resilience as maintenance slows.
52%
Total Score
50
100
81
75
The package is about 14 months old with 26 releases, but only 2 releases in the last 12 months and no release since December 2025, indicating slowed maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months; combined with the December 2025 latest release, this is a meaningful maintenance concern.
Composer is used for builds, but no security scanning tools were detected, leaving a security-hygiene gap without making the package unfit by itself.
The repository has no security policy, so there is no documented security-reporting path for a payment integration.
v0.0.26 is not a stable major release, so its pre-1.0 status adds maturity and compatibility risk despite having no recent prereleases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0 | — | — |
spatie/laravel-data Version ^4.0 | — | — |
saloonphp/pagination-plugin Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.