Package Health

guanguans/yii-pay

The source project has a clear MIT license, tests, release notes, security tooling, and an active-looking repository, but registry publishing stopped four years ago and recent commit activity is absent. GitHub Actions also use an unpinned container image, adding a supply-chain hygiene concern.

Latest v1.2.3PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Health Score Breakdown

Release historycaution

The package has 12 releases, but none in the last four years; this materially raises maintenance and compatibility risk despite a previously regular median release interval of about 28 days.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, which indicates no recent development activity; the later push timestamp does not show sustained maintenance.

Workflow auditcaution

All 12 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in php-cs-fixer.yml. No untrusted checkout or script-injection path was found, limiting this to a hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

guanguans

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ^2.0
—
—
yansongda/pay
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform