Package Health

formancehq/formance-sdk-php

This release is actively produced and transparently tied to the matching Formance organization repository: it has 70 releases over roughly 3.7 years, seven releases in the last 12 months, a stable non-prerelease version, a recent repository push, and two active contributors. However, Packagist explicitly marks this package as abandoned and names formance/formance-sdk as its replacement, which is a severe adoption concern even though repository activity remains current. The lack of tests, absent security policy, limited repository popularity, and incomplete workflow permission hardening add caution. Developers should prefer the replacement package unless compatibility requirements specifically require this release.

Latest v7.0.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and identifies formance/formance-sdk as the replacement. This is a severe dependency-health concern because continued use may leave consumers on a superseded package, despite the other evidence of active development.

Package scaffoldingcaution

The artifact has a substantial README, but both the package and repository report no tests and no changelog. The repository does contain RELEASES.md and uses GitHub Releases, which partially compensates for changelog absence, but the lack of tests remains a maintenance-hygiene gap.

Repo issue activitycaution

The repository has 3 open issues, with 2 new issues and no closed issues in the last month; one pull request was merged. This suggests some unresolved maintenance demand despite ongoing activity.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 2 watchers. Popularity is limited and provides little external validation, though low popularity alone is not evidence of abandonment.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are reported. Build support is adequate while security-process visibility is limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
brick/math
Version >=0.12.1
brick/date-time
Version >=0.7.0
galbar/jsonpath
Version >=3.0
guzzlehttp/guzzle
Version ^7.0
speakeasy/serializer
Version ^4.0.3

Weekly Downloads

Info

Last Published
11 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform