Usable with caveats: this is a newly published package with no established release or commit history, and its library package has no README for integration guidance. Tests, an MIT declaration, active repository status, and organization backing provide some support, but maturity is not yet demonstrated.
58%
Total Score
75
100
71
83
The package has no README even though it is a framework integration library that consumers must configure and use, creating a real documentation gap. Repository tests are present, which provides some compensating evidence for implementation quality.
The package is 0 days old with only 2 releases, both published within about 30 minutes, so there is not enough history to demonstrate release stability or long-term maintenance.
The repository reports 0 commits and 0 active maintainers in the last 3 months, but the package and repository are brand new, so this is better interpreted as unproven maintenance capacity than as clear abandonment.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a modest transparency gap rather than a severe dependency-health issue.
No repository security policy is present, leaving vulnerability-reporting expectations unclear for a payment-related integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stripe/stripe-php Version ^13.0 | — | — |
veldora/framework Version ^0.6.0|^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.