Package Health

shubhamdhaboya/stripe-php

Risky to adopt: this release has not been updated since September 2020, and the linked repository shows no recent commits or contributor activity. It is clearly packaged, licensed, and tested in the repository, but the long abandonment gap outweighs those strengths.

Latest v7.53.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has a substantial history with 293 releases, but its latest release was over 5 years ago and it had no releases in the last 12 months. That prolonged inactivity is a significant maintenance and abandonment concern.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last 3 months. Combined with the old last push, this is strong evidence that maintenance has effectively stopped.

Project backingcaution

The repository is owned by a personal user account rather than an organization, and the registry maintainer list contains only one entry. This leaves a thin visible backing structure for a package that has had no recent activity.

Repo issue activitycaution

There were no new or merged pull requests and no issue activity in the last month. This provides no evidence of ongoing responsiveness and is consistent with the stale repository.

Repo toolingcaution

The repository uses Make and Composer build tooling, showing some project structure, but it has no detected security scanning tools. The tooling is a modest positive while the missing scanning is a hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stripe and contributors

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform