Healthy and usable, with some early-project caveats. It has frequent stable releases, recent commits from two contributors, a clear README, and a security policy, but it is only 169 days old and has no tests or security scanning reported.
78%
Total Score
75
100
83
100
One registry maintainer account publishes the package, which is a limited publishing base. The linked repository is user-owned rather than organization-owned, so there is less visible institutional backing to offset that concentration.
The repository is owned by an individual user rather than an organization, so maintenance responsibility appears concentrated in a personal project.
The package has made 14 releases in 169 days, including releases within the last 42 days, showing active publication. The very short median interval of about 33 minutes suggests an unusually rapid early release cadence, so maturity is not yet proven.
The repository has only three stars, one fork, and no watchers, indicating limited adoption evidence. Popularity is supporting evidence rather than a decisive health measure, especially for a specialized package.
Composer build tooling is present, but no security scanning tools are reported. This is a transparency and process gap for payment-related code, although it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0|^13.0|^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.