Package Health

tappay/laravel-tap-payment

The package has clear documentation, tests, and release notes, with recent repository activity. Its single-contributor maintenance base and permissive, entirely unpinned workflow setup warrant extra care for production use.

Latest v1.4.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-maintainer and concentrated-contribution concerns are not offset by visible organizational backing.

Repo bus factorcaution

All four recent commits came from one contributor, leaving the project dependent on a single maintainer if that person becomes unavailable.

Repo commit activitycaution

Four commits from one active maintainer in the last 3 months show ongoing work, though the modest volume limits evidence of sustained maintenance capacity.

Workflow auditcaution

All nine workflows were analyzed, but all 44 action references are unpinned and seven workflows grant top-level write permissions. High-confidence template-injection findings in release workflows are hygiene concerns here because no untrusted checkout or injection sink was reported alongside them.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Waqas Majeed

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^11.0 || ^12.0 || ^13.0
—
—
guzzlehttp/guzzle
Version ^7.10
—
—
illuminate/routing
Version ^11.0 || ^12.0 || ^13.0
—
—
illuminate/support
Version ^11.0 || ^12.0 || ^13.0
—
—
illuminate/database
Version ^11.0 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform