Package Health

verbb/commerce-payflow

Healthy and suitable to use, with a small maintenance team as the main caveat. It has a current stable release, established history, organizational backing, licensing, and a linked active repository, but recent work is concentrated in one contributor and the project has no automated security scanning.

Latest 4.0.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Package scaffoldingcaution

The package includes a README and changelog, and the repository uses GitHub Releases; missing tests are a modest transparency gap because no repository tests are present either.

Repo bus factorcaution

All recent commits came from one contributor, creating concentration risk; organizational backing partly compensates because maintenance can be handed off within the organization.

Repo commit activitycaution

One commit was recorded in the last 3 months, showing some recent activity but a very limited maintenance cadence.

Repo popularitycaution

The repository has only 3 stars and 4 forks, which provides little community validation, but low popularity alone does not outweigh the package's other evidence.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are configured, leaving a security-hygiene gap for a payment-related package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Verbb

Direct Dependencies

DependencyLast ReleaseScore
verbb/base
Version ^3.0.0
craftcms/cms
Version ^5.0.0
omnipay/payflow
Version ^3.0.0
craftcms/commerce
Version ^5.0.0
craftcms/commerce-omnipay
Version ^4.1.0

Weekly Downloads

Info

Last Published
6 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform