laravel+vue for b2b2c.
57%
Total Score
caution
Usable with caveats: maintenance stopped after October 2024 and the license metadata conflicts.
The repository recorded no commits and no active maintainers in the last 3 months; together with the old latest release, this points to stalled maintenance.
The artifact declares MIT and includes license files, so it is not unlicensed, but detected Apache-2.0 text conflicts with the declaration and requires legal clarification.
The package runs four Composer lifecycle hooks, including post-install and post-update actions; these are operationally significant because installation executes package-provided code.
The package has 97 releases since March 2021, but none in the last 12 months and its latest release was over 1 year ago, indicating a meaningful maintenance gap.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that supports payments and user accounts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yansongda/pay Version ~3.1 | — | — |
laravel/tinker Version ^2.5 | — | — |
laravel/sanctum Version ^2.11 | — | — |
laravel/passport Version ^10.1 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.