Tests, documentation, and release notes make integration easier. Long-term support still depends heavily on a single active contributor.
68%
Total Score
67
86
67
The package has had 4 releases over 531 days and 2 releases in the last 12 months, with a median interval of about 7 months; this indicates a modest maintenance pace rather than abandonment.
One contributor made all 5 recent commits, creating a meaningful continuity risk even though the repository is owned by an organization that could potentially provide handoff capacity.
There were 5 commits in the last 3 months, showing recent work, but the activity is limited and concentrated in one active maintainer.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance-hygiene gap.
The repository has no security policy, leaving disclosure and response expectations undocumented for a package that handles billing integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafs/sprout Version ^5.0 | — | — |
pestphp/pest Version * | — | — |
leafs/alchemy Version ^5.0 | — | — |
friendsofphp/php-cs-fixer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.