A JavaScript PDF generation library
90%
Total Score
100
100
94
67
50
No build attestation or trusted-publisher provenance was provided, so consumers cannot independently verify how the registry artifact was produced.
The project uses established build and test tools, including Rollup and Vitest. No security scanning tools were detected, leaving a minor process gap.
No repository security policy was found, which reduces transparency about vulnerability reporting and handling.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Both action references are unpinned, a reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fflate Version ^0.8.3 | — | — |
png-js Version ^2.0.0 | — | — |
fontkit Version ^2.0.4 | — | — |
linebreak Version ^1.1.0 | — | — |
@noble/hashes Version ^1.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.