Clear documentation, tests, changelog, and licensing make the integration easier to evaluate. Organization backing and recent repository activity help, but the project is only 62 days old.
68%
Total Score
67
100
79
75
The package is only 62 days old with three releases, spaced about 31 days apart. This shows ongoing publication but provides limited long-term maintenance evidence.
All two recent commits came from one contributor, giving the project a complete short-term contributor concentration. Organization backing provides some handoff capacity but does not demonstrate a second active contributor.
The repository had two commits in the last three months, with activity from one maintainer. Recent activity exists, but the volume is thin for establishing durable maintenance.
The project uses Make and Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
No SECURITY.md or other repository security policy was detected. For a package handling Stripe billing and webhooks, the lack of a reporting path modestly reduces transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/cashier Version ^16.0 | — | — |
laravel/framework Version ^11.0|^12.0 | — | — |
whilesmart/eloquent-entitlements Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.