Package Health

pay-now/paynow-magento2

The package has clear documentation, tests, a matching repository, and recent releases. Maintenance is concentrated in one contributor, and the repository has no security policy or scanning, so continuity and security transparency remain concerns.

Latest 2.0.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts, which increase installation-time execution surface and warrant extra scrutiny when adopting updates.

Repo bus factorcaution

One contributor made all 5 commits in the last 3 months, leaving no demonstrated second contributor to provide maintenance continuity. Organization ownership offers some handoff capacity but does not remove the observed concentration.

Repo commit activitycaution

The repository has 5 commits in the last 3 months, showing recent work, but all activity is concentrated in a single active maintainer.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are detected, leaving an avoidable gap in the project's security hygiene.

Security policycaution

The repository has no security policy or documented security-reporting path, reducing transparency for handling vulnerabilities in a payment integration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

mElements S.A.

Direct Dependencies

DependencyLast ReleaseScore
nyholm/psr7
Version ^1.2
—
—
firebase/php-jwt
Version ^6.4 || ^7.0
—
—
magento/framework
Version >=101
—
—
magento/module-sales
Version >=101
—
—
php-http/curl-client
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform