Package Health

eugenefvdm/billing

Compatibility and long-term support remain uncertain for this young v0.x package. Tests, licensing, and security scanning are reassuring, but the stalled repository and unpinned workflow actions add maintenance and build-reproducibility risk.

Latest v1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, following a last push about 10 months ago. For a payment package, this is a meaningful sign of stalled maintenance.

Release historycaution

The package is 320 days old with five releases, but all five arrived within roughly four days and none followed during the remaining period. That burst does not demonstrate sustained maintenance.

Security policycaution

No security policy is present. That is a transparency gap for a package handling payment and billing flows, even though GitGuardian scanning provides partial compensation.

Version stabilitycaution

The latest version is v0.4 and is not a stable major release, so compatibility and API maturity remain less certain for a Laravel billing integration.

Workflow auditcaution

The single workflow was fully analyzed with no injection or high-severity findings, but both of its action references are unpinned. This leaves builds exposed to moving action revisions and is a moderate reproducibility concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eugene van der Merwe

Direct Dependencies

DependencyLast ReleaseScore
spatie/ray
Version *
moneyphp/money
Version *
symfony/dotenv
Version *
guzzlehttp/psr7
Version *
guzzlehttp/guzzle
Version *

Weekly Downloads

Info

Last Published
10 months ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform