Usable with caveats: it is a licensed, documented, stable Laravel package with repository tests, but it has had no release or commit activity for about two years and has limited security and community support signals.
55%
Total Score
50
100
83
63
A post-autoload-dump lifecycle script runs during installation, which warrants some review because install-time execution increases exposure, but no dangerous behavior is shown by this signal alone.
The package and repository are owned by the same individual account, with no organization backing shown; this is workable but provides a thinner continuity signal.
Only three releases have been published, with no release in the last two years; this is a meaningful maintenance concern for a payment-integration library.
There have been zero commits and zero active maintainers in the last three months, consistent with the package having effectively stalled since its last 2024 release.
The repository has zero stars, forks, and watchers, offering no evidence of a broader user or maintainer community to help sustain it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version >=9.0 | — | — |
guzzlehttp/guzzle Version >=7.2 | — | — |
illuminate/config Version >=9.0 | — | — |
illuminate/support Version >=9.0 | — | — |
illuminate/contracts Version >=9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.