The README is clear, the MIT license is declared, and installation has no lifecycle scripts. Missing security scanning and a security policy leave weaker transparency for a payment integration.
52%
Total Score
50
83
75
The latest release was over two years ago, with no releases in the last 12 months. That materially raises abandonment risk for a payment integration, though the package is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the prolonged release gap and limited evidence of ongoing maintenance.
Composer is used for builds, but no security-scanning tools are configured. That leaves dependency and source checks less demonstrable than they could be.
The linked repository has no security policy. This is a transparency gap for a package handling payment flows, although it does not by itself show a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.