The package includes tests, a readable README, release notes, and no install-time scripts. Its MIT declaration conflicts with the MIT-0 license found in the artifact, while release and commit activity stopped about 18 months ago.
57%
Total Score
75
100
81
75
The artifact contains a license file, but the manifest declares MIT while the detected license is MIT-0. That mismatch creates a real licensing-transparency concern despite the presence of license files.
Only two releases were published, both within minutes on 9 March 2025, with no releases in the following 12 months. This indicates a very short and inactive release history for a package handling payment integrations.
There were no commits and no active maintainers in the past three months. Combined with the 18-month-old last push, this is evidence of stalled maintenance.
Composer build tooling is present, but no security-scanning tools are configured. For a package that handles authentication and payouts, the missing scanning coverage is a modest transparency gap.
The repository has no security policy. That makes vulnerability reporting and response expectations unclear for a package integrating with payment APIs.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.