Package Health

lava-payment/lava

Lava Payment SDK

Latest v2.1.0PackagistPackagist

62%

Total Score

caution

Usable with caveats: maintenance is concentrated in one contributor and the workflow uses an unpinned container image.

Health Score Breakdown

Project backingcaution

The repository owner is an individual account, so the concentrated contributor activity is not visibly supported by an organization.

Repo bus factorcaution

One contributor made all recent commits, leaving maintenance fully concentrated in a single person. The repository owner is an individual rather than an organization, so there is no shown organizational handoff to offset this.

Repo commit activitycaution

Only one commit was recorded in the last three months, which is limited recent maintenance for an SDK handling payment integrations.

Security policycaution

The repository has no security policy, reducing transparency about how payment-related vulnerabilities should be reported and handled.

Workflow auditcaution

All workflows use read-only permissions and the audit completed fully, but the high-confidence audit found an unpinned container image. This is a reproducibility and build-hygiene concern, not a severe risk by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform