Clear documentation, tests, changelog, and a matching repository make the package straightforward to evaluate. One maintainer and no security scanning leave limited backup if maintenance or security work is needed.
58%
Total Score
50
100
88
50
The registry has one publishing maintainer. That is a thin operational base for a payment package, and the repository is owned by an individual rather than an organization, so there is limited visible backup.
The repository and registry are both owned by the same individual account, and no organization backing is shown. This is consistent ownership but does not provide organizational maintenance capacity.
The package has only two releases, both published within minutes on its launch day, with no later release activity over roughly seven months. That is a meaningful maturity and maintenance concern for a payment integration.
Composer build tooling is present, but no security scanning tools are reported. The missing scanning is a hygiene gap for a package handling payment and webhook functionality.
The repository has no security policy. That makes vulnerability reporting and response expectations less transparent for a security-sensitive integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.