The MIT license, README, and release notes make the package understandable to integrate. Maintenance is uncertain because no release has shipped in over a year, recent commits are absent, and the workflows have broad permissions, unpinned actions, and a high-confidence bot-condition finding.
58%
Total Score
50
86
50
The package has eight releases, but none in the last 12 months and the latest release was over a year ago, which weakens confidence in ongoing maintenance.
The repository shows zero commits and zero active maintainers in the last three months, despite a recent push being recorded elsewhere; this is a meaningful maintenance concern.
This release is v0.2.0-alpha, and all recent releases are prereleases, so the API and behavior may still change substantially.
All nine analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding may allow actor context to be spoofed. The pull_request_target workflow has no untrusted checkout or script-injection findings, limiting the risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^v12.0.1 | — | — |
quickpay/quickpay-php-client Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.