Clear README, tests, and MIT licensing support adoption, and the owning organization provides some continuity. Treat this as an early, lightly validated dependency and pin the version.
59%
Total Score
75
79
50
The package is 190 days old but has only one release, so there is not yet enough release history to demonstrate sustained maintenance.
The repository recorded 0 commits and 0 active maintainers in the last three months, leaving ongoing maintenance unproven despite the recent initial publication.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and hygiene gap rather than evidence of abandonment.
No security policy was found, which reduces disclosure transparency for a package handling payment integration and webhook signatures.
The current v0.1.0 release is pre-1.0, which signals an immature API and higher compatibility risk for adopters.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/events Version ^10.0|^11.0|^12.0 | — | — |
zevpay/zevpay-php Version ^0.1 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.