Clear documentation, tests, and a valid license make the project easy to inspect. Its stable release line and recent repository activity provide useful reassurance despite the limited maintenance depth.
68%
Total Score
67
93
50
The package runs post-autoload-dump, post-create-project-cmd, post-root-package-install, and post-update-cmd scripts; this is relevant supply-chain exposure, though such scripts are plausible for a Laravel demo application.
The registry has one publishing maintainer, which leaves limited release-management redundancy; the linked repository is also user-owned rather than organization-backed.
One contributor made 100% of the last 3 months' commits, creating a real continuity risk with no provided organizational backing to compensate for it.
Composer build tooling is present, but no security-scanning tooling was detected, leaving an avoidable quality and maintenance gap.
The repository has no published security policy, leaving reporting and response expectations unclear for a package that demonstrates payment integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fakerphp/faker Version ^1.24 | — | — |
laravel/octane Version ^2.13 | — | — |
laravel/tinker Version ^2.10.1 | — | — |
laravel/framework Version ^12.0 | — | — |
nwidart/laravel-modules Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.