Package Health

paddlehq/paddle-php-sdk

This is a generally credible, actively published PHP SDK with a clear Apache-2.0 license, substantial package contents, documentation, changelog, repository tests, security policy, dependency scanning, and safe-analyzed workflows. The release history is regular and the repository is organization-backed, correctly linked, and not archived. However, the repository reports zero commits and zero active maintainers in the last 3 months, while issue closure is limited, creating a meaningful maintenance-continuity concern despite the very recent release and push; one workflow also lacks top-level token permissions. It is usable as a dependency, but adopters should monitor future releases and repository activity.

Latest v1.18.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package declares 16 runtime dependencies, which is a moderate integration surface for a full-featured API SDK; this is a consideration but not an acute health problem.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers over the last 3 months. This is a meaningful maintenance-continuity concern, although the recent release and repository push partially offset the abandonment signal.

Repo issue activitycaution

There were 2 new issues and no issues closed in the last month, with no new pull requests and 1 merged pull request, indicating limited recent issue-resolution activity.

Token permissionscaution

Two workflows declare read-only permissions, but release-on-push.yml lacks top-level permissions. The absence is a workflow-hygiene gap, though no top-level write permissions were observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Paddle and contributors

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
symfony/uid
Version ^5.4 || ^6.3 || ^7.0 || ^8.0
myclabs/php-enum
Version ^1.8
php-http/httplug
Version ^1.1 || ^2.0
php-http/message
Version ^1.5

Weekly Downloads

Info

Last Published
11 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform