The package is licensed and its repository is active and correctly identified, but it is only one day old and has no commits in the past three months. A single publisher and no security policy leave limited evidence of long-term maintenance.
64%
Total Score
67
100
88
50
Only one registry publishing account is listed, which is a modest resilience concern. The organization-owned repository provides some backing, so this is not evidence of abandonment by itself.
The package is only 1 day old, with 4 releases arriving roughly every 2.9 hours. That shows active initial publishing but provides little evidence of an established maintenance track record.
The repository reports 0 commits and 0 active maintainers during the past 3 months. Because the package is only 1 day old and was pushed today, this is limited maturity evidence rather than proof of abandonment.
Composer build tooling is present, but no security-scanning tools were detected. That is a maintenance and transparency gap for a package handling storefront, checkout, and payment-related functionality.
The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities in a package with broad application functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/money Version ^0.15.2 | — | — |
composer/semver Version ^3.4 | — | — |
laravel/sanctum Version ^4.3 | — | — |
tightenco/ziggy Version ^2.4 | — | — |
kalnoy/nestedset Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.