Package Health

tpay/magento2

The project has a long release history, frequent recent releases, and recent changes from two contributors. Its automation and package-to-repository identity need tightening before treating builds as fully trustworthy.

Latest 2.9.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

Two contributors were active in the last three months, which provides some handoff capacity, although one contributor made 75% of commits. The concentration is a mild resilience concern rather than a severe single-maintainer risk.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although name differences can be normal, both indicators together leave the package-to-source relationship insufficiently clear.

Security policycaution

No repository security policy was found. For a payment module handling transaction and token flows, the lack of a documented vulnerability-reporting path reduces transparency.

Workflow auditcaution

All four workflows were analyzed, but all 10 action references are unpinned, and high-confidence template-injection findings appear in the release workflow while an artipacked finding appears in pull-request automation. These workflow weaknesses warrant caution around build and release integrity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

tpay.com

Direct Dependencies

DependencyLast ReleaseScore
psr/simple-cache
Version ^1
—
—
tpay-com/tpay-php
Version ^2.4.7
—
—
tpay-com/tpay-openapi-php
Version ^2.4.7
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform