AltaPay/api-php 3.6.2 appears healthy and suitable for dependency use: it has a long release history dating to 2016, 59 releases with 8 in the last 12 months, a stable non-prerelease version, current repository activity, clear MIT licensing, substantial source and documentation structure, tests, changelog coverage, and no deprecation or install-time lifecycle scripts. The main reservations are that recent repository work is concentrated in one contributor, the repository has no security policy, and its workflows do not declare top-level token permissions; these are meaningful governance and resilience gaps, although organization backing, active releases, build/security tooling, and safe workflow analysis provide compensating evidence.
82%
Total Score
90
100
100
80
All six recent commits came from one contributor, creating a genuine concentration risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is shown.
The repository has no SECURITY.md or equivalent security policy, leaving vulnerability reporting and disclosure expectations undocumented.
Both workflows omit top-level token permissions declarations. Although neither grants explicit top-level write access, the absence of least-privilege declarations weakens CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
symfony/event-dispatcher Version ^2.1 || ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
symfony/options-resolver Version ^2.6 || ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.