Clear documentation, tests, release notes, and licensing make the package straightforward to evaluate and integrate. Its young history, single active contributor, and workflow hygiene leave less operational depth than a mature project.
78%
Total Score
88
100
89
50
Three releases in the first 100 days, with a median interval of about 34 days, show active early maintenance but provide limited evidence of long-term maturity.
One contributor made all four recent commits, leaving maintenance dependent on a single individual despite organizational ownership.
The project uses Composer and Make, but no security-scanning tooling was observed, leaving a modest repository-hygiene gap.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not evidence of unsafe code by itself.
All four workflows were analyzed with no untrusted checkouts or script injection, but all six action references are unpinned, two release workflows grant top-level write access, and a high-confidence low-severity audit found an ad hoc package install.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
whilesmart/eloquent-payments Version ^1.0 | — | — |
whilesmart/eloquent-customers Version ^2.0 | — | — |
whilesmart/eloquent-owner-access Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.