Package Health

gbxnga/payaza-laravel-sdk

It includes a substantial README, a matching repository, tests, and security scanning. Workflow references are all unpinned and the repository lacks a security policy, limiting maintenance confidence.

Latest v1.0.52PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has eight releases, but all appear concentrated within roughly 25 minutes and there have been no releases for about 14 months. That pattern suggests an abandoned or one-off launch rather than ongoing maintenance.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, while its last push was in July 2025. The lack of recent activity is a meaningful abandonment concern.

Security policycaution

No security policy was found in the repository. This is a transparency gap, although it is less significant than the maintenance concerns.

Workflow auditcaution

All 13 analyzed action references are unpinned, which weakens build reproducibility. The high-confidence template-injection finding is hygiene risk here because no untrusted trigger or checkout sink was reported; the low-confidence cache-poisoning finding adds little weight.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^10.0|^11.0|^12.0
—
—
guzzlehttp/guzzle
Version ^7.8
—
—
illuminate/support
Version ^10.0|^11.0|^12.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform