Package Health

mahocommerce/module-pensopay

Usable with caveats: it is actively released, licensed, backed by an organization, and has matching source with automated checks. Maintenance is concentrated in one contributor, while the repository lacks a security policy and mostly omits explicit workflow permissions.

Latest 4.0.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Dangerous workflowscaution

Seven workflows were analyzed and one uses pull_request_target, which warrants care because that trigger can expose elevated workflow context to pull requests. No untrusted checkouts or script-injection patterns were detected.

Repo bus factorcaution

One contributor made all five recent commits, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

Five commits were made in the last three months, showing current activity, but all activity came from one maintainer.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a payment integration.

Token permissionscaution

Six workflows lack top-level permissions declarations, and one workflow declares write access. Explicit least-privilege permissions would make the build and release process more transparent and safer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform