The repository includes tests, a changelog, security guidance, and automated static and dependency analysis. Its workflows have no detected dangerous triggers or findings, but every analyzed action reference is unpinned, weakening build reproducibility.
63%
Total Score
50
93
100
The latest release was in January 2024, with no releases in the last 12 months; this is a meaningful maintenance concern for a billing integration, despite 12 releases overall.
The repository recorded zero commits and zero active maintainers in the last 3 months, indicating little recent development activity.
All four workflows were analyzed with no dangerous triggers, injection findings, or audit findings, but all 23 action references are unpinned, which weakens supply-chain reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version >=0.8.0 | — | — |
nesbot/carbon Version >=1.26 | — | — |
illuminate/http Version ^7.0 || ^8.0 | — | — |
illuminate/view Version ^7.0 || ^8.0 | — | — |
illuminate/routing Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.