Dodo Payments PHP SDK
72%
Total Score
caution
Frequent releases and organization backing help, but one recent contributor and a high-confidence workflow credential finding temper confidence.
All recent commits come from one contributor, creating concentration risk; organization ownership provides some ability to hand maintenance off, so this is caution rather than a severe standalone risk.
Only one commit was recorded in the last three months, with one active maintainer; this is a meaningful maintenance-capacity concern even though registry releases remain frequent.
All four workflows were analyzed, references are fully pinned, and no untrusted checkout or script injection was found. However, a high-confidence audit finding reports that the release workflow's GitHub App token inherits blanket installation permissions, creating a workflow-permission hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1 | — | — |
psr/http-message Version ^1|^2 | — | — |
php-http/discovery Version ^1 | — | — |
psr/http-client-implementation Version ^1 | — | — |
psr/http-factory-implementation Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.