Package Health

hyprpay/payments

hyprpay/payments v0.17.0 appears usable and actively developed, with a linked non-archived repository, extensive documentation, tests, changelog and release infrastructure, a clear MIT license, no install-time scripts, and no registry deprecation. The package is nevertheless only 28 days old, has a very rapid release cadence, low adoption indicators, and all 117 recent commits come from one contributor, creating meaningful continuity and maturity risk. The repository also lacks automated security scanning and grants top-level write permissions to two workflows, so dependency adoption is reasonable with review and monitoring rather than yet demonstrating mature, low-risk maintenance.

Latest v0.17.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 13 runtime dependencies, including several Laravel components and JWT support. This is a meaningful dependency surface for a payment SDK, though the explicit Composer declarations make the integration footprint visible.

Project backingcaution

The linked repository is owned by an individual user, not an organization, so the single-maintainer and bus-factor concerns are not compensated by demonstrated organizational ownership.

Release historycaution

The package has 28 releases in 28 days, with a median interval of about 17 hours. This demonstrates active iteration but also indicates a very young project whose release process and API stability have had limited time to mature.

Repo bus factorcaution

One contributor made 100% of the 117 commits in the last three months, creating a substantial single-maintainer continuity risk. The repository owner is a user rather than an organization, so there is no provided organizational backing to compensate for this concentration.

Repo commit activitycaution

The repository recorded 117 commits in the last three months, showing strong recent activity, but all activity came from one active maintainer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
illuminate/log
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—
illuminate/auth
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—
illuminate/http
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—
illuminate/view
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform