The package includes tests, a substantial README, a changelog, and a clear MIT license. It is extremely new, with only two releases on the same day, and the repository has no security policy or scanning tools yet.
72%
Total Score
100
78
75
Only two releases exist, both within the first day of publication, so there is not yet enough history to demonstrate sustained maintenance or stability.
The repository has zero stars, forks, and watchers. For a package published on the same day this is expected early-stage evidence, but it provides no external maturity support yet.
Composer build tooling is present, but no security-scanning tools are reported. That is a modest transparency gap for a payment integration, though it is not evidence of unsafe code by itself.
The repository has no security policy. This weakens the documented process for reporting vulnerabilities, particularly for a package handling payment and webhook integrations.
The release is an early 0.1.1 version rather than a stable major release, which signals an immature compatibility and maintenance track even though it is not marked prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/view Version ^12.0|^13.0 | — | — |
vexpay/vexpay-php Version ^0.1 || ^0.2 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.