The project is small and lightly documented, with no tests or security policy. Organization ownership and a recent release provide some continuity, but long gaps between releases and complete reliance on one recent contributor limit confidence.
62%
Total Score
67
100
79
75
A short README is present, and the absence of tests and a changelog in the published artifact is normal packaging practice. The repository also has no tests or changelog, leaving limited evidence of validation and release documentation.
The package has only two releases in 374 days, with a median interval of about 11 months and one release in the last 12 months; this indicates slow maintenance, though a recent release exists.
One contributor made all four commits in the last three months, creating a concentrated maintenance dependency. Organization backing partly offsets handoff risk, but no second active contributor is shown.
Four commits were made in the last three months, showing recent activity, but the activity is limited in volume.
Composer is used for builds, but no security scanning tools were detected, leaving supply-chain hygiene less demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafs/billing Version ^5.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.