The package includes tests, a changelog, and a clear MIT license. Its organization-backed repository has two active contributors, while all four workflow actions are unpinned.
78%
Total Score
100
79
83
The package is 53 days old with three releases and a median interval of about 15 days, showing active early development but limited long-term history.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest assurance gap for a library handling payment-related integrations.
The repository has no security policy. This is a transparency and issue-reporting gap, though it is not by itself evidence of abandonment.
Version v0.1.3 is not a stable-major release, so its API may change more readily than a mature 1.x package. It is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or write permissions, but all four referenced actions are unpinned. Pinning them would improve build reproducibility and reduce action-supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
guzzlehttp/promises Version ^2.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.