Package Health

korozcolt/payments-slim

The package is clearly documented, tested, licensed, and tied to a matching repository. Its two releases arrived within minutes, so maintenance over time is not yet demonstrated; the workflow also uses two unpinned actions.

Latest v1.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The package is maintained under a user-owned repository rather than an organization, so the small apparent ownership base provides limited backing evidence.

Release historycaution

This is a brand-new package with two releases in the same day and a median interval of about 12 minutes, so long-term maintenance is not yet established.

Repo commit activitycaution

No commits or active maintainers were recorded in the last three months, but this repository is newly created, so the result mainly shows that a longer maintenance history is unavailable.

Security policycaution

No security policy is present, which is a modest transparency gap for a package handling payment integrations.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. Both action references are unpinned, which weakens build reproducibility but is not a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^1.0|^2.0
—
—
korozcolt/payments-core
Version ^1.0
—
—
psr/http-server-handler
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
23 hours ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform