Healthy and usable, with some maturity and security-process caveats. The package has recent releases, substantial documentation and tests, and active organization-backed development, but all recent commits come from one contributor and the repository has no security policy or scanning tool.
78%
Total Score
83
88
67
All six recent commits came from one contributor, creating a genuine continuity risk if that person becomes unavailable. Organization ownership partly compensates by providing a potential handoff path.
Composer build tooling is present, but no security scanning tools were detected, leaving a gap in automated security hygiene for a payment-related package.
The repository has no security policy, so users lack an established process for reporting vulnerabilities in a package that handles billing and payment integrations.
The only workflow does not declare top-level token permissions. It does not request top-level write access, but explicit least-privilege permissions would provide clearer CI safety.
Version v0.1.1 is not a stable major release, so its API may still change and it carries more adoption risk than a mature 1.x package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.