Package Health

mrcmorales/payum-redsys

The project has tests, a matching MIT license, and a release with notes, but registry publishing stopped about 18 months ago and recent commit activity is absent. The repository also lacks security scanning and pins neither of its two workflow actions.

Latest v1.7.1PackagistPackagist

63%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Only two releases exist, with the latest published about 18 months ago and none in the last 12 months. That makes ongoing compatibility and maintenance less certain.

Repo commit activitycaution

The repository recorded no commits and no active maintainers during the last three months. This is a direct sign of currently limited maintenance activity.

Repo toolingcaution

Composer is used for the build, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Both of its two action references are unpinned, leaving avoidable dependency-update risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marc Morales Valldepérez
Payum project
Community contributions

Direct Dependencies

DependencyLast ReleaseScore
payum/core
Version ^1.7
—
—
php-http/message-factory
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform