The package has a clear README, changelog, repository tests, and an MIT license. Its small team, inactive release history, and recent lack of commits make future compatibility less certain, while workflow pinning needs attention.
55%
Total Score
75
88
50
The package has 23 releases and historically released about every 6 days, but it has had no release in roughly two years. That sustained pause raises maintenance and compatibility concerns.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the repository is not archived, the current lack of development activity weakens confidence in ongoing maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a payment integration. Dependabot provides some compensating security tooling, but it does not replace a reporting policy.
Version 0.16 is not a prerelease and recent releases contain no prerelease versions, although the pre-1.0 major version leaves more room for breaking changes than a stable major release.
All 12 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lunarphp/lunar Version * | — | — |
srmklive/paypal Version ^3.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.