Package Health

dodopayments/client

Dodo Payments PHP SDK

Latest v6.29.0PackagistPackagist

72%

Total Score

caution

Frequent releases and organization backing help, but one recent contributor and a high-confidence workflow credential finding temper confidence.

Health Score Breakdown

Repo bus factorcaution

All recent commits come from one contributor, creating concentration risk; organization ownership provides some ability to hand maintenance off, so this is caution rather than a severe standalone risk.

Repo commit activitycaution

Only one commit was recorded in the last three months, with one active maintainer; this is a meaningful maintenance-capacity concern even though registry releases remain frequent.

Workflow auditcaution

All four workflows were analyzed, references are fully pinned, and no untrusted checkout or script injection was found. However, a high-confidence audit finding reports that the release workflow's GitHub App token inherits blanket installation permissions, creating a workflow-permission hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/http-client
Version ^1
—
—
psr/http-message
Version ^1|^2
—
—
php-http/discovery
Version ^1
—
—
psr/http-client-implementation
Version ^1
—
—
psr/http-factory-implementation
Version ^1
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform