Documentation, tests, and a matching repository make the package transparent, while the organization backing it supports continuity. Its small user base, missing security policy, and unpinned workflow actions leave less independent assurance than a mature dependency.
68%
Total Score
75
89
67
The repository shows zero commits and zero active maintainers in the last three months. Although the package was released recently, this leaves weak evidence of ongoing development between releases.
The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is not disqualifying, but it provides little independent evidence of broad review or adoption.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
konekt/concord Version ^1.18 | — | — |
vanilo/payment Version ^6.0 | — | — |
vanilo/contracts Version ^6.0 | — | — |
laravel/framework Version ^12.61.1|^13.12 | — | — |
mollie/mollie-api-php Version ^2.68 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.