Documentation, tests, and licensing are in place. The project is very young, and its sole contributor plus unpinned CI actions leave limited maintenance and build assurance.
62%
Total Score
50
81
75
The repository is owned by an individual account rather than an organization, so there is no provided evidence of organizational maintenance capacity to offset the concentrated contributor base.
The package is only 32 days old and has two releases, both published within about four hours. That shows initial activity but gives little evidence of long-term maintenance.
All four recent commits came from one contributor, giving the project a very low bus factor and making maintenance continuity dependent on a single person.
Four commits were made in the last three months, showing some recent activity, but the small volume provides only limited evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a package handling payment integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/cache Version ^11.0 || ^12.0 || ^13.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
laravel/socialite Version ^5.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.