Package Health

esanj/payment-client

This is a usable but very young package with positive maintenance signals: it is not deprecated or archived, has received four releases over 47 days, was pushed recently, and has a clear MIT license, documentation, and a small focused dependency footprint. However, adoption carries meaningful maintenance risk because the repository has only one active contributor with all four recent commits, no tests or changelog, no security policy or scanning tooling, and no observable issue or pull-request activity. The package is therefore suitable for controlled use when its API and payment-service dependency are well understood, but it should not yet be treated as a mature, low-risk foundational dependency.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Eight runtime dependencies are reasonable for a Laravel HTTP client, though the package depends on the separate esanj/auth-bridge package and external service integration, increasing operational coupling.

Maintainerscaution

Only one registry account, Esanj, has publishing access. This is a limited publishing base and adds continuity risk, although registry access alone does not establish actual maintenance activity.

Package scaffoldingcaution

A substantial README is present, but both the artifact and repository lack tests and a changelog. For a payment client, the absence of repository tests is a genuine maintenance and regression risk.

Project backingcaution

The repository owner is a user account rather than an organization, so the concentrated contributor activity is not compensated by organizational handoff capacity.

Release historycaution

Four releases in 47 days, with a median interval of about 16 days, show active early development; the short history still leaves long-term maintenance unproven.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Esanj

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0|^3.0
illuminate/log
Version ^12.0|^13.0
illuminate/http
Version ^12.0|^13.0
esanj/auth-bridge
Version >=1.0.0 <2.0.0
guzzlehttp/guzzle
Version ^7.0

Weekly Downloads

Info

Last Published
16 days ago
Created
16 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform