Package Health

bitpay/sdk

The package has clear documentation, tests, licensing, and a steady release history. Its workflow dependencies are not pinned and the repository has no security policy, while recent commit activity is absent; monitor future maintenance closely.

Latest 10.1.4PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. Recent releases and merged pull requests provide some continuing activity, but the lack of direct commit activity is a meaningful maintenance caution.

Security policycaution

The repository has no published security policy. For a payment API client, that reduces transparency about vulnerability reporting and handling.

Workflow auditcaution

All 3 workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, or injection findings. However, all 8 action references are unpinned, which leaves build automation exposed to moving dependencies.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Antonio Buedo

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^5.4 || ^6.4 || ^7.0
symfony/console
Version ^4.4 || ^5.4 || ^6.4 || ^7.3.1
bitpay/key-utils
Version ^2.1
guzzlehttp/guzzle
Version ^7.9
netresearch/jsonmapper
Version ^5.0

Weekly Downloads

Info

Last Published
2 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform