Package Health

zoujingli/think-plugs-payment

This release appears usable and actively maintained, with a non-archived repository, a recent push, six commits in the last three months, stable versioning, tests, and no install-time lifecycle scripts or dangerous workflow patterns. However, adoption carries meaningful transparency and continuity concerns: no license declaration or license file was found, all recent repository commits come from one contributor, the repository has minimal external interest, no security policy or scanning is present, and its release workflow grants top-level write permissions. The package is therefore suitable only after reviewing its proprietary/VIP usage terms and accepting single-maintainer and repository-security risk.

Latest v1.0.17PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Licensecaution

Neither a declared license nor a license file was found, creating a genuine licensing and transparency concern for consumers; the artifact's README describes VIP authorization terms, but that does not compensate for the absent machine-readable or file-based license evidence.

Project backingcaution

The repository owner is an individual user rather than an organization, so there is no demonstrated organizational maintenance handoff to offset the concentrated contributor base.

Repo bus factorcaution

One contributor made all six commits in the last three months, producing a 100% top-contributor share and a genuine continuity risk for a user-owned project with no organizational backing shown.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher, so there is little external corroboration or community visibility. Popularity is supporting evidence rather than decisive, but the very small footprint modestly increases adoption risk.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured; the build setup is adequate while the missing security automation is a modest hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anyon

Direct Dependencies

DependencyLast ReleaseScore
zoujingli/think-plugs-admin
Version ^1.0|@dev
zoujingli/think-plugs-account
Version ^1.0|@dev

Weekly Downloads

Info

Last Published
11 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform