Package Health

pronko/converge-payment-library

The single-maintainer project has no security policy and uses a proprietary license, limiting transparency and adoption flexibility. A README, changelog, release notes, and stable version provide useful documentation, but do not offset the age of the codebase.

Latest 1.0.2PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

Only two releases were published, both in August 2017, with no releases in the last 12 months and no newer activity observed. This strongly raises abandonment risk for a payment integration.

Licensecaution

The manifest declares a proprietary license and a LICENSE file is present in both the package and repository, so this is licensed rather than an unlicensed release. The proprietary terms may still constrain dependency use and transparency.

Maintainerscaution

One registry maintainer is consistent with a small project, but the repository owner is an individual rather than an organization, leaving little visible maintainer redundancy after years without activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tooling was detected. This is a modest supply-chain hygiene gap, not evidence that the release is unsafe by itself.

Repository archivedcaution

The repository is not archived, which avoids the strongest abandonment signal, but its last push was August 18, 2017 and therefore does not show ongoing maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pronko Consulting

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
9 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform