Package Health

korozcolt/payments-symfony

The README, tests, MIT license, and matching repository make the package easy to inspect. It is newly published, and its CI uses two unpinned actions without a security policy; pin those actions before relying on automated builds.

Latest v1.0.1PackagistPackagist

71%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is brand new, with only two releases published within minutes and no long-term release record. That limits evidence of maturity, though the rapid v1.0.1 follow-up is not itself a negative maintenance signal.

Repo commit activitycaution

There were no commits in the preceding three months and no active maintainers in that window, but the repository and release were created only moments before collection, so this is an immature history rather than evidence of abandonment.

Security policycaution

The repository has no security policy, leaving no published process for reporting or handling vulnerabilities in a payment integration package.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned. That is a supply-chain hygiene gap, not a severe risk by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.8
—
—
symfony/config
Version ^6.4|^7.0
—
—
symfony/console
Version ^6.4|^7.0
—
—
symfony/routing
Version ^6.4|^7.0
—
—
symfony/http-client
Version ^6.4|^7.0
—
—

Weekly Downloads

Info

Last Published
23 hours ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform