Frequent releases, a stable version, tests, and an organization-owned repository support adoption. The small community and unpinned workflow actions leave less depth for long-term assurance.
72%
Total Score
88
100
89
83
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a meaningful maintenance pause, although the latest release was recent.
The repository has 3 stars, 0 forks, and 0 watchers, indicating limited external adoption and a small feedback community; this is supporting caution rather than a standalone adoption blocker.
Composer build tooling is present, but no security-scanning tool was detected. That leaves a modest assurance gap for a payment-related package.
The repository has no published security policy, reducing transparency about vulnerability reporting and response.
The single workflow was fully analyzed with no injection, dangerous-trigger, or audit findings. However, both action references are unpinned, so workflow dependencies are less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moneyphp/money Version ^4.7 | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.