An MCP (Model Context Protocol) server for the Credo payment gateway, powered by zowesoft/laravel-credo.
78%
Total Score
healthy
A brand-new v0.2.0 package with tests and release notes, but no established maintenance track record yet.
The package is only 0 days old with two releases, so there is not yet enough history to demonstrate sustained maintenance. The second release and current repository push provide some early activity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap, while the build setup itself is appropriate.
The repository has no security policy, leaving no documented vulnerability-reporting process. This is a hygiene gap for a package that handles payment integrations.
Version v0.2.0 is not a stable major release, which indicates an early-stage API and less maturity. It is not marked as a prerelease, partially offsetting the concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injections, or audit findings. Both action references are unpinned, which weakens reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^1.0 | — | — |
illuminate/contracts Version ^11.45.3|^12.41.1|^13.0 | — | — |
zowesoft/laravel-credo Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.