Package Health

vanilo/mollie

Documentation, tests, and a matching repository make the package transparent, while the organization backing it supports continuity. Its small user base, missing security policy, and unpinned workflow actions leave less independent assurance than a mature dependency.

Latest 4.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

The repository shows zero commits and zero active maintainers in the last three months. Although the package was released recently, this leaves weak evidence of ongoing development between releases.

Repo popularitycaution

The repository has only 2 stars, 0 forks, and 1 watcher. Low popularity is not disqualifying, but it provides little independent evidence of broad review or adoption.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vanilo UG

Direct Dependencies

DependencyLast ReleaseScore
konekt/concord
Version ^1.18
—
—
vanilo/payment
Version ^6.0
—
—
vanilo/contracts
Version ^6.0
—
—
laravel/framework
Version ^12.61.1|^13.12
—
—
mollie/mollie-api-php
Version ^2.68
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform