Skip to content
CAI
Software that uses CAICheck a score

yansongda/pay

71.3

Strong · 19 September 2026

29.2k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a PHP library that provides a unified, plugin-based interface for integrating with a wide variety of payment gateways, including Alipay, WeChat Pay, Stripe, PayPal, and several regional providers. It abstracts the complexities of distinct API versions and authentication methods by standardizing core operations such as payments, refunds, queries, and webhook handling through a consistent service provider architecture. The library manages provider-specific configuration, certificate handling, and request signing, allowing developers to interact with multiple payment services using a single, cohesive codebase.

How it got here

2017–2022 — Architecture modernization and provider expansion

20 changes.

This period focused on modernizing the SDK's core architecture by introducing typed configuration, centralized certificate management, and a standardized service provider registration system. It simultaneously expanded payment gateway support to include major providers like Stripe, PayPal, and Airwallex, while migrating the documentation site to VitePress.

2023–2024 — Artful framework migration and V3 API expansion

31 changes.

The codebase underwent a comprehensive architectural shift to adopt the yansongda/artful plugin pipeline, rewriting shortcut and plugin layers for Alipay, WeChat, Unipay, and Jiangsu Bank to use standardized request construction and signature handling. This migration enabled significant feature expansion, including full support for WeChat Pay V3 APIs, new payment channels like Douyin and Airwallex, and enhanced multi-channel capabilities across existing providers.

2026 — multi-provider payment integration expansion

23 changes.

This period focused on expanding the library's payment gateway support by adding full V2 and V3 integrations for PayPal, Stripe, Alipay, and WeChat, alongside new providers like Airwallex, Allinpay, and BestPay. The work included implementing core plugin architectures, shortcut classes, and provider-specific traits to handle authentication, transactions, and webhooks. Comprehensive test coverage was added for all new features, and the configuration system was refactored to use strongly-typed objects for improved validation and reliability.

Features

Add Airwallex payment gateway support

Introduces a new Airwallex payment provider plugin (V1) enabling users to process payments, confirm transactions, cancel orders, query payment and refund statuses, issue refunds, and handle webhook callbacks. The implementation includes plugins for obtaining access tokens, verifying webhook signatures, and managing the request/response lifecycle specific to the Airwallex API.

src/Plugin/Airwallex · high confidence

Add Alipay OpenAPI V3 support

Introduces a new V3 integration layer for Alipay, adding dedicated plugins for request signing, HTTP request construction, and response signature verification, alongside shortcut classes that wire these plugins for standard operations including POS payments, QR code pre-creation, transaction queries, refunds, cancellations, and order closures.

src/Plugin/Alipay/V3, src/Shortcut/Alipay/V3 · high confidence

Add Allinpay (通联支付) Provider Support

Introduces a new payment provider for Allinpay (apiweb main chain), enabling users to process payments and manage transactions via the Allinpay gateway. This change adds the necessary plugin chain (including signature generation, request building, and response validation) and shortcut classes to support unified payments, native/scan QR payments, refunds, transaction queries, and order closures.

src/Plugin/Allinpay, src/Shortcut/Allinpay · high confidence

Add Home page components for authorization and primary actions

The documentation site now includes dedicated Vue components for the Home page layout. The new Authorize.vue component displays licensing information for the library (MIT) and documentation (CC BY-SA 4.0), while Primary.vue renders the site logo and a 'Quick Start' call-to-action button linking to the v3 documentation.

web/.vitepress/theme/components/Home · high confidence

Add Jiangsu Bank (Jsb) e-Rong payment plugin

Introduces a new payment provider for Jiangsu Bank e-Rong, including plugins for scanning payments, refunds, and queries, as well as core plugins for request signing, signature verification, callback handling, and response validation.

src/Plugin/Jsb · high confidence

Add PayPal payment shortcuts

New shortcut classes have been added to the PayPal integration to support order queries, refunds, and web-based payments. The \QueryShortcut\ handles order and refund lookups, \RefundShortcut\ processes refund requests, and \WebShortcut\ manages initial payments and captures, all utilizing the V2 plugin chain for token acquisition and response parsing.

src/Shortcut/Airwallex, src/Shortcut/Paypal · high confidence

Add Unipay Qra (Barcode/Scan) payment plugin

Introduces a new plugin set for UnionPay's barcode payment (Qra) service, enabling merchants to accept payments via scanned QR codes (native) and POS card swipes (micropay). This addition includes dedicated plugins for the full transaction lifecycle: initiating payments, handling callbacks, querying order status, processing refunds, and verifying signatures, all implemented using the new Artful API request framework.

src/Plugin/Unipay/Qra · high confidence

Add WeChat Pay Score (PayScore) V3 API plugins

Added a new set of plugins under \src/Plugin/Wechat/V3/PayScore\ to support the WeChat Pay Score (PayScore) V3 API. This includes \CreatePlugin\, \QueryPlugin\, \PayPlugin\, \CancelPlugin\, \CompletePlugin\, \ModifyPlugin\, and \SyncPlugin\ for managing service orders, as well as \Permissions/CreatePlugin\, \Permissions/QueryPlugin\, and \Permissions/TerminatePlugin\ for handling pre-authorizations (signing). These plugins enable merchants to create, query, pay, cancel, complete, modify, and sync PayScore orders, as well as manage user permissions, strictly in normal merchant mode.

src/Plugin/Wechat/V3/PayScore · high confidence

Add WeChat V3 Complaints and Profit Sharing plugins

This change introduces new plugin classes in the WeChat V3 Extend directory to support two additional WeChat Pay V3 API areas. The Complaints plugins (Complete, DeleteCallback, QueryCallback, QueryDetail, QueryImage, QueryNegotiation, Query, Response, SetCallback, UpdateCallback, UpdateRefund) enable merchants to manage customer complaints, including querying details, handling callbacks, and updating refund progress. The Profit Sharing plugins (AddReceiver, Create, DeleteReceiver, DownloadBill, GetBill, QueryAmounts, QueryMerchantConfigs, Query, QueryReturn, Return, Unfreeze) provide full lifecycle support for profit sharing operations, including adding/removing receivers, creating and querying orders, handling returns, and unfreezing funds.

src/Plugin/Wechat/V3/Extend · high confidence

Add WeChat V3 Marketing plugins for coupons, e-commerce refunds, and blockchain invoices

This change introduces a comprehensive set of new plugin classes under \src/Plugin/Wechat/V3/Marketing\ to support WeChat Pay V3 marketing features. Specifically, it adds plugins for managing coupon stocks (create, query, pause, restart, start, and flow queries), distributing and querying coupons, handling callback notifications, and managing e-commerce refunds (apply, query by ID or merchant number, and advance return operations). Additionally, it includes plugins for the blockchain invoice module, enabling the creation of tax-controlled invoices with sensitive data encryption, downloading invoice files, and retrieving base information and tax codes. These plugins standardize the API request assembly for these marketing endpoints.

src/Plugin/Wechat/V3/Marketing · high confidence

Add initial BestPay (YiPay) integration plugins and shortcuts

This change introduces the first phase of support for the BestPay (YiPay) payment provider. It adds a complete set of V1 plugins and shortcuts to handle core payment operations, including H5, Web, and Scan-to-Pay flows, as well as order query, refund, and close actions. The implementation includes specific plugins for assembling the request payload with signature logic (aligning with the official Java SDK behavior), constructing the HTTP radar request, verifying callback and response signatures using platform public keys, and validating API responses.

src/Plugin/Bestpay, src/Shortcut/Bestpay · high confidence

Add support for WeChat Mini Program virtual payments

Introduces a new plugin set under \src/Plugin/Wechat/Virtual\ to enable WeChat Mini Program virtual payment flows. This includes \PayPlugin\ and \AddPayloadSignaturePlugin\ for client-side signature generation and server-side API calls, \CallbackPlugin\ for handling encrypted webhook notifications, and specialized plugins for currency management (pay, cancel, query balance, present), goods operations (upload, publish, query), order lifecycle (query, refund, download bill), subscription contracts, and withdrawals.

src/Plugin/Wechat/Virtual · high confidence

AddRadarPlugin for Unipay barcode payment integration

A new AddRadarPlugin has been introduced in the Unipay plugin directory to support the barcode payment (scanned payment) feature. This component constructs the HTTP request payload and headers required for interacting with the UnionPay barcode payment gateway, utilizing the Artful API request framework and the UnipayTrait for configuration handling.

src/Plugin/Unipay · high confidence

Alipay V2 plugin architecture and expanded API coverage

The Alipay integration has been migrated to the V2 plugin structure, replacing the previous implementation with a new set of components built on the \yansongda/artful\ request framework. This update introduces dedicated plugins for handling request signing (\AddPayloadSignaturePlugin\), HTTP request construction (\AddRadarPlugin\), and callback verification (\AppCallbackPlugin\). It significantly expands supported Alipay capabilities by adding new plugins for fund operations (royalty settlement, transfers, PC credit installment payments), marketing features (red packets), member services (identity certification, face verification, OCR), and merchant tools (item file uploads). Additionally, it adds support for third-party ISV authorization via \TokenAppPlugin\ and fixes signature validation logic for app callbacks.

src/Plugin/Alipay/V2 · high confidence

Custom VitePress theme with integrated home and documentation components

The documentation site now uses a custom VitePress theme that extends the default layout to inject specific Vue components into key areas: a primary hero section at the top of the home page, an authorization feature section below the home features, and an additional outline section in the documentation sidebar.

web/.vitepress/theme · high confidence

Initial repository structure and documentation setup

This change establishes the foundational project structure by adding essential configuration and documentation files. It includes \.gitattributes\ and \.gitignore\ to manage repository exports and local artifacts, coding standards via \.php-cs-fixer.php\, and CI/CD configuration in \.scrutinizer.yml\. It also introduces \AGENTS.md\ to document the SDK's architecture, plugin pipeline, and security practices, alongside \SECURITY.md\ for vulnerability reporting guidelines. The \CHANGELOG.md\ is initialized with release notes for v3.8.0-beta.6, detailing new providers (BestPay, Allinpay), Alipay OpenAPI V3 support, and Douyin payment migration, while \README.md\ provides installation instructions and usage examples for the supported payment gateways.

(repo-wide) · high confidence

Introduce PayPal V2 payment integration

Adds a complete set of V2 plugins for PayPal, enabling order creation, capture, refund, and query operations, along with access token management, webhook callback handling, and signature verification.

src/Plugin/Paypal · high confidence

Introduction of new event classes for payment lifecycle and HTTP operations

New event classes have been added to the \src/Event\ directory to expose specific moments in the payment and HTTP processing flows. \PayStart\ and \PayEnd\ now allow listeners to hook into the beginning and completion of payment operations, carrying details such as the active plugins and request parameters. Similarly, \HttpStart\ and \HttpEnd\ provide visibility into the lifecycle of HTTP requests. Additionally, \CallbackReceived\ enables handling of incoming payment callbacks with provider-specific data, while \MethodCalled\ exposes details about invoked methods, including the provider, method name, and arguments.

src/Event · high confidence

New Alipay callback and gateway verification plugins

Added \CallbackPlugin\ and \GatewayCallbackPlugin\ to handle Alipay asynchronous notifications and application gateway verification (ISV). \CallbackPlugin\ processes V2 form-parameter callbacks by filtering parameters, sorting keys, and performing RSA2 signature verification, while \GatewayCallbackPlugin\ handles the \alipay.service.check\ gateway protocol, including specific logic for \verifygw\ events that return the app public key, and constructs signed XML responses for success or failure cases.

src/Plugin/Alipay · high confidence

New exception classes for decryption and signature errors

The library now includes dedicated exception classes to provide more specific error handling for common payment issues. A new \DecryptException\ has been added to handle encryption and decryption failures, with specific error codes for WeChat and Alipay ciphertext/encrypted data issues. Additionally, an \InvalidSignException\ is introduced to specifically catch signature verification errors, storing the callback data for easier debugging. These classes extend the base \Exception\ class, which has been updated with a comprehensive set of error codes covering parameters, responses, configuration, and signatures for various payment providers.

src/Exception · high confidence

New payment providers and action constants added

This release introduces support for several new payment gateways: Airwallex, Allinpay (UnionPay Web), BestPay (YiPay), Jsb (Bank of Jiangsu), PayPal, Stripe, and Unipay (UnionPay). It also adds dedicated action constant classes (e.g., AlipayAction, WechatAction) to standardize operation identifiers across providers. Existing providers like Alipay and Wechat have been updated to support new capabilities such as Alipay OpenAPI V3, Alipay ISV app authorization, WeChat OAuth, and WeChat PayScore.

src/Provider · high confidence

New provider traits for Airwallex, Allinpay, Bestpay, Douyin, Jsb, PayPal, Stripe, and Unipay

The library now includes dedicated trait implementations for eight additional payment providers, providing the core logic for URL resolution, signature generation, and webhook verification. This adds support for Airwallex, Allinpay (Tonglian), Bestpay (YiPay), Douyin (TikTok), Jsb (Jiangsu Bank), PayPal, Stripe, and Unipay (UnionPay). Each trait handles provider-specific requirements such as OAuth token management (Airwallex, PayPal, Douyin), certificate-based signing (Allinpay, Bestpay, Jsb, Unipay), and webhook signature validation with anti-replay protection (Airwallex, PayPal, Stripe, Douyin).

src/Traits · high confidence

Stripe V1 payment plugin implementation

This change introduces the Stripe V1 payment integration, adding a complete set of plugins to handle core payment operations. The new components include PayPlugin for creating PaymentIntents, WebPlugin for Checkout Sessions, and RefundPlugin for issuing refunds. It also adds support for querying and canceling PaymentIntents (QueryPlugin, CancelPlugin), querying refunds (QueryRefundPlugin), and processing webhooks (CallbackPlugin). Additionally, AddRadarPlugin handles request assembly with proper headers and body formatting, while ResponsePlugin validates API responses.

src/Plugin/Stripe · high confidence

Stripe payment integration shortcuts

Added five new shortcut classes (CancelShortcut, IntentShortcut, QueryShortcut, RefundShortcut, WebShortcut) in the Stripe namespace to handle specific payment operations. These shortcuts define the plugin pipeline for canceling payments, creating payment intents, querying order or refund status, processing refunds, and handling webhooks, thereby enabling Stripe payment functionality within the application.

src/Shortcut/Stripe · high confidence

Unipay shortcuts now support H5, POS, and cancellation operations

The Unipay shortcut implementation has been expanded to cover additional payment scenarios. Users can now process H5 payments via the new H5Shortcut, and POS transactions are supported through PosShortcut, which handles default, pre-auth, and QRA (QR code) actions. Additionally, a new CancelShortcut enables cancellation of web, QR code, and QRA POS payments, while existing Web, Scan, and Query shortcuts have been updated to route these specific actions via a unified match-based dispatch system.

src/Shortcut/Unipay · high confidence

WeChat OpenAPI OAuth and Token Management Plugins

Added new plugin classes in the WeChat OpenAPI domain to support OAuth user identity capabilities. This includes \GetStableTokenPlugin\ for obtaining stable tokens, and a suite of OAuth plugins (\Code2SessionPlugin\, \WebAccessTokenPlugin\, \RefreshTokenPlugin\, \UserInfoPlugin\) for handling WeChat Mini Program and Web authorization flows. A dedicated \ResponsePlugin\ was also added to validate HTTP status codes and business error codes for these open API responses.

src/Plugin/Wechat/Openapi · high confidence

WeChat V2 API support expanded with new plugins and multi-channel invocation

The WeChat V2 plugin directory has been significantly expanded to support additional payment flows and invocation methods. New plugins now enable WeChat direct debit (Papay) operations including application, contract order, and mini-program-only contract workflows. Support for Point-of-Sale (POS) payments has been added, covering micropayments, query, and cancellation actions. Additionally, the library now supports sending WeChat red packets (hongbao) and provides dedicated InvokePlugins for generating the necessary client-side configuration for App, Mini Program, and Mobile Web (JSAPI) payment invocations.

src/Plugin/Wechat/V2 · high confidence

WeChat V3 App and Combined Payment Plugin Implementation

This change introduces a comprehensive set of new plugin classes for the WeChat V3 payment integration, specifically targeting the App and Combined (aggregated) payment scenarios. The diff adds dedicated plugins for standard App transactions (Pay, Query, Refund, Close, and Bill retrieval) as well as Combined transactions (App, H5, Jsapi, and Mini Program pay, invoke, and bill operations). These plugins standardize the request assembly for WeChat API v3 endpoints, handling merchant ID configuration, service mode routing, and signature generation, thereby enabling users to process App payments and complex combined orders through the updated V3 architecture.

src/Plugin/Wechat/V3/Pay · high confidence

Wechat V3 API support with signature and callback handling

Added new plugin classes in src/Plugin/Wechat/V3 to support the Wechat V3 API, including AddPayloadSignaturePlugin for generating V3 signatures, CallbackPlugin for processing and decrypting Wechat callbacks, VerifySignaturePlugin for verifying incoming signatures, and WechatPublicCertsPlugin for fetching public certificates.

src/Plugin/Wechat/V3 · high confidence

Behavioural changes

Alipay shortcuts restructured for multi-channel and third-party authorization support

The Alipay shortcut classes in this directory have been rewritten to support a broader range of payment channels (App, H5, Mini Program, POS, Scan, Web) and new operational modes. The new implementation introduces dedicated shortcut classes for each channel (e.g., AppShortcut, H5Shortcut) and refactors complex operations like Cancel, Close, Query, and Refund to use a unified action-based dispatch system. This allows the library to handle specific sub-actions (such as agreement, authorization, or mini-program variants) within a single shortcut class, and adds support for third-party ISV token app authorization via the new AuthShortcut.

src/Shortcut/Alipay · high confidence

Douyin payment plugin migrated to official general trade system

The Douyin payment integration has been replaced with a new V1 plugin set that implements Douyin's official general trade system. This update introduces new plugins for JSAPI order invocation (InvokePlugin), order and refund querying, refund creation and auditing, and unified callback handling (CallbackPlugin). It also adds client token management (GetClientTokenPlugin, ObtainClientTokenPlugin) and request/response processing (AddRadarPlugin, ResponsePlugin). This is a breaking change that removes the previous escrow-based payment implementation.

src/Plugin/Douyin · high confidence

Douyin payment shortcuts now use snake\_case \_action dispatch

The Douyin payment integration has been refactored to unify action handling across MiniShortcut, QueryShortcut, and RefundShortcut. These shortcuts now accept a snake\_case \\_action\ parameter (e.g., \order\, \cps\, \refund\) to dispatch to specific plugin chains via a match statement, replacing the previous implicit or different dispatch mechanism. This change standardizes how query, refund, and mini-program order operations are triggered within the Douyin shortcut layer.

src/Shortcut/Douyin · high confidence

Introduces centralized certificate management and typed provider configuration

The library now includes a new \CertManager\ class that centralizes the handling, parsing, and caching of certificates (including WeChat serial-number-based caching, Alipay SN extraction, and UnionPay PKCS12 support) to improve performance and reduce redundant file I/O. Additionally, the \Config\ class has been refactored to use typed configuration objects (e.g., \WechatConfig\, \AlipayConfig\) for each supported provider, replacing the previous flat array approach and ensuring stricter validation and type safety when accessing provider settings.

src · high confidence

Migrate web documentation site to VitePress

The web documentation has been migrated to VitePress, replacing the previous static site generator. This introduces a new build toolchain using Vite and TypeScript, configured via vite.config.ts and tsconfig.json, and includes a custom theme with SCSS styling for the home page layout. Configuration files such as .editorconfig, .gitignore, and .node-version (set to Node 20) have been added to support the new environment.

web · high confidence

Migration to VitePress with Algolia DocSearch

The documentation site has been migrated to VitePress, replacing the previous static site generator. This change introduces a new configuration structure in web/.vitepress/config.ts, enabling Algolia DocSearch for improved documentation discoverability and updating the site's branding and navigation settings.

web/.vitepress · high confidence

New provider and provider configuration interfaces introduced

Two new interfaces, ProviderInterface and ProviderConfigInterface, have been added to the contract layer. ProviderInterface defines the core payment operations (pay, query, cancel, close, refund, callback) and specifies that order-related parameters (order) must be passed as arrays. ProviderConfigInterface defines methods for retrieving tenant, mode, and generic configuration values, as well as a validate method to ensure configuration completeness.

src/Contract · high confidence

Restructured documentation navigation and sidebar configuration

The documentation site now uses dedicated configuration files for navigation and sidebars. A new navigation menu (nav.ts) organizes content by version status, grouping v1.x under 'End of Life', v2.x under 'Security Support', and v3.x under 'Active Development'. The sidebar configuration (sidebar.ts) has been refactored to dynamically load sidebar data for each version directory using fast-glob, replacing the previous static or manual setup.

web/.vitepress/config · high confidence

Standardized payment provider registration via service providers

Payment providers (Alipay, Wechat, Stripe, PayPal, Airwallex, Allinpay, Bestpay, Douyin, Unipay, Jsb) are now registered through dedicated service provider classes that extend a new AbstractServiceProvider. This change standardizes how providers are instantiated and bound to the container, ensuring consistent initialization across all supported payment gateways.

src/Service · high confidence

Typed configuration objects replace raw arrays for all payment providers

The configuration system has been migrated from raw associative arrays to strongly-typed PHP classes (e.g., \AlipayConfig\, \WechatConfig\, \AirwallexConfig\) that extend a new \AbstractConfig\ base. This change introduces centralized validation logic, ensuring that required fields (like \appId\, \mchId\, or \secretKey\) are present and that the \mode\ setting is valid before any payment operation begins. Users benefit from immediate, clear error messages if configuration is incomplete or invalid, rather than encountering cryptic failures later in the request pipeline. The new structure also standardizes how provider-specific settings are accessed and managed across the library.

src/Config · high confidence

Unipay Open API plugin implementation using Artful framework

The Unipay Open API integration has been restructured into a new plugin set (\AddPayloadSignaturePlugin\, \CallbackPlugin\, \ResponseHtmlPlugin\, \StartPlugin\, \VerifySignaturePlugin\) that leverages the \yansongda/artful\ API request framework. This change introduces a standardized plugin pipeline for handling Unipay Open API requests, including automatic payload signing, signature verification for callbacks and responses, and HTML form generation for redirects, while migrating configuration retrieval to the new \getProviderConfig\ method.

src/Plugin/Unipay/Open · high confidence

Unipay Open Pay plugins migrated to Artful framework and UnipayTrait

The Unipay Open Pay plugin implementations (H5, Web, and QrCode) have been rewritten to use the \yansongda/artful\ API request framework instead of the previous internal HTTP client. This migration introduces the \UnipayTrait\ for shared logic and standardizes configuration retrieval via the new \getProviderConfig\ method, replacing the deprecated \get\_xxx\_config\ pattern. Additionally, all API endpoint URLs in the payload are now normalized to a leading \/\ format, and the plugins consistently use \QueryPacker\ for request formatting.

src/Plugin/Unipay/Open/Pay · high confidence

Updated v3 documentation sidebar with new payment providers and features

The v3 documentation sidebar has been expanded to include quick-start guides and detailed API references for newly supported payment providers: Airwallex, Allinpay, BestPay, Douyin, JSB (Jiangsu Bank), PayPal, Stripe, and UnionPay. Additionally, new documentation sections have been added for WeChat Pay features including Virtual Payment, PayScore, and OAuth User Identity, as well as Alipay's third-party application authorization (ISV) support.

web/.vitepress/sidebar · high confidence

WeChat shortcuts restructured to use Artful plugin pipeline

The WeChat shortcut classes (App, H5, Mini, Jsapi, Native, Pos, Refund, Query, Transfer, Cancel, Oauth, Papay, PayScore, Redpack, Virtual) have been rewritten to implement the \ShortcutInterface\ from the \yansongda/artful\ framework. Instead of direct API calls, these shortcuts now define a sequence of plugins (such as \StartPlugin\, \PayPlugin\, \AddPayloadSignaturePlugin\, \VerifySignaturePlugin\, and \ResponsePlugin\) to handle request preparation, signing, execution, and response parsing. This change aligns the WeChat integration with the new internal API request framework, ensuring consistent plugin-based behavior across all payment types.

src/Shortcut/Wechat · high confidence

Wechat plugin refactoring and new RadarPlugin

The Wechat plugin directory has been refactored to support the new Artful API request framework. A new AddRadarPlugin has been introduced to handle the construction of HTTP requests (method, URL, headers, body) for Wechat interactions, utilizing the WechatTrait for configuration retrieval. The existing ResponsePlugin has been updated to validate HTTP response status codes, throwing an InvalidResponseException for non-2xx responses. These changes align with the broader migration to the Artful framework and the introduction of WechatConfig type annotations.

src/Plugin/Wechat · high confidence

Test coverage

Added edge-case tests for payment callbacks and network errors; Added stub classes for testing service providers and parsers; Added test certificates and keys for payment providers; Added test stub for Alipay service provider plugin; Added test stubs for WeChat plugin callbacks and virtual payments; Added tests for AbstractServiceProvider registration; Added tests for Alipay V3 payment integration; Added tests for Alipay callback and gateway verification plugins; Added tests for BestPay integration plugins and certificates; Added tests for Unipay Open plugin components; Added unit tests for Airwallex V1 payment plugins; Added unit tests for Alipay and WeChat V2 App payment plugins; Added unit tests for Alipay shortcut plugin compositions; Added unit tests for CertManager, Pay configuration, and payment provider shortcuts; Added unit tests for Jiangsu Bank (Jsb) payment plugins; Added unit tests for PayPal V2 payment plugins; Added unit tests for Stripe payment shortcuts; Added unit tests for Unipay AddRadarPlugin; Added unit tests for Unipay shortcut plugins; Added unit tests for WeChat OpenAPI OAuth and token plugins; Added unit tests for WeChat Shortcut plugin pipelines; Added unit tests for WeChat V3 App and Combine Pay plugins; Added unit tests for WeChat V3 Complaints and Profit Sharing plugins; Added unit tests for WeChat Virtual Payment plugins; Added unit tests for Wechat AddRadar and Response plugins; Added unit tests for Wechat V3 signature and certificate plugins; Added unit tests for payment provider traits; Added unit tests for provider configuration validation; Expanded test coverage for new and existing payment providers.

Dependencies

Update core PHP dependencies and upgrade web documentation tooling

The library now requires PHP 8.2 and pins the internal HTTP client framework \yansongda/artful\ to version 1.2.0 and \yansongda/supports\ to 4.1.0. Development dependencies have been upgraded to PHPUnit 11.5, Mockery 1.6, Monolog 3, and Symfony 6.4 components, with \guzzlehttp/guzzle\ supporting versions 7.0 or 8.0. For the documentation site, \vitepress\ is updated to alpha 2.0 and \vite\ to 8.2.2, requiring Node.js 20.12.0 or higher.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 71.

Lenses

  • Code Health 98
  • Architecture 96
  • Maturity 57
  • Readiness 82
  • Security 93
  • Accessibility 78

Changes since last survey

  • 300 commits — 243 feature/other, 57 fixes

By area

  • (root) — 85 commits
  • src/Plugin — 81 commits
  • web/docs — 30 commits
  • tests/Plugin — 24 commits
  • web/.vitepress — 20 commits
  • src/Provider — 11 commits
  • src/Shortcut — 9 commits
  • web/package.json — 8 commits
  • .agents/skills — 5 commits
  • web/pnpm-lock.yaml — 4 commits
  • src/Config — 3 commits
  • src/Exception — 3 commits
  • src/Service — 3 commits
  • src/Direction — 2 commits
  • (repo) — 1 commit
  • .github/workflows — 1 commit
  • docs/static-instantiation.md — 1 commit
  • docs/superpowers — 1 commit
  • src/Config.php — 1 commit
  • src/Functions.php — 1 commit

Notable commits

  • fix: Fixed undefined array key wechat_public_cert_path when don't set it. (#674)
  • fix: fix(docs): fix analystics (#851)
  • fix: fix(docs): fix docs sidebar (#849)
  • fix: fix(paypal): 消除请求 body 中的业务参数残留并加强回调防御 (#1196)
  • fix: fix(stripe): 消除查询/取消/退款查询请求中的内部参数残留并加强校验 (#1198)
  • fix: fix(style): fix coding styles (#866)
  • fix: fix(wechat): 修复虚拟支付配置校验、signData 顺序与 access_token 自动获取问题 (#1188)
  • fix: fix(wechat): 添加回调时间戳验证防止重放攻击 (#1168)
  • fix: fix: CallbackReceived 事件在获取到回调参数后触发 (#716)
  • fix: fix: alipay 中 event dispatch provider 是 wechat 的问题 (#595)
  • fix: fix: app 支付调起签名中参数大小写问题
  • fix: fix: app 支付调起签名中时间戳参数大小写问题 (#510)
  • fix: fix: app 支付调起签名问题
  • fix: fix: changelog 版本错误 (#825)
  • fix: fix: destination 的类型约束去掉 array (#824)
  • fix: fix: json 中有 & 时解析错误 (#687)
  • fix: fix: monolog 不存在时报错问题 (#834)
  • fix: fix: readme badge (#821)
  • fix: fix: 事件缺失与不生效的问题 (#1106)
  • fix: fix: 修复 Trait 静态方法调用的 deprecation warnings (#1147)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

yansongda/pay was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d1b354bc7808d00b75dd7b2038eb5359e90bafec — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.