Package Health

payflex/prestashop-gateway

This release is usable but carries meaningful maturity and continuity concerns. It is a stable, non-deprecated package backed by an organization-owned repository that was pushed recently, uses build tooling, and has a clean workflow-risk profile. However, the package is extremely new with only two releases, has no tests or changelog, has only one active contributor responsible for all recent commits, lacks a security policy, and uses top-level write permissions in its workflow. The repository backing and organization ownership partially mitigate the narrow maintainer base, but the limited history means developers should adopt it with monitoring and a contingency plan.

Latest 2.1.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

The package includes a substantive README and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. For a payment integration, the absence of visible tests is a genuine maintenance and verification gap.

Release historycaution

Only two releases exist and both were published within the same day, leaving almost no observed maintenance history or evidence of sustained release cadence.

Repo bus factorcaution

One contributor made all three commits in the last three months, creating a narrow operational bus factor. Organization ownership partly mitigates handoff risk, but no second active contributor is evidenced.

Repo commit activitycaution

Three commits occurred in the last three months, showing recent maintenance, but all activity is concentrated in a single active maintainer. The activity is positive but still thin for a payment integration.

Repo issue activitycaution

There are no open issues or pull requests and no activity in the last month. This is ambiguous for a newly published repository: it provides no evidence of community engagement, but it also does not show unresolved maintenance backlog.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Payflex

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
18 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform