The package has only 49 days of history, five recent commits, and modest adoption, so long-term reliability is not yet proven. Clear licensing, tests, release notes, organizational backing, and a second active contributor help offset that; workflow references remain unpinned.
70%
Total Score
83
100
83
83
At 49 days old with only two releases, the package has too little history to demonstrate long-term maintenance or stability. The second release and recent repository activity provide some support but do not remove the maturity gap.
Two contributors are active, but one accounts for 80% of the five recent commits. The second contributor and organization backing provide partial resilience, so this is a modest concentration concern rather than a severe risk.
The repository has zero stars, forks, and watchers. This is supporting evidence of limited adoption, though low popularity alone does not establish poor maintenance.
Composer build tooling is present, but no repository security-scanning tool was detected. For a package handling billing and webhooks, that is a modest transparency and maintenance gap.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for a package handling payment integrations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.