Package Health

alves/nfse-php-brazil

This is a usable but very young package with substantial implementation evidence: version v2.0.0 is stable, the artifact contains tests, extensive source structure, documentation, and no install-time lifecycle scripts. Maintenance is currently active, with 9 commits in the last 3 months and a repository pushed recently, but all recent work comes from one contributor and the project has no observed adoption signals, security policy, or security scanning. The rapid release cadence over only 98 days also leaves long-term stability unproven. Depend on it with normal validation and monitoring, particularly because its municipal integration and provider catalog are operationally significant.

Latest v2.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package has 10 runtime dependencies, including two PDF libraries and several extensions; this is a meaningful integration surface and increases compatibility and maintenance burden, though the profile is explicit.

Maintainerscaution

Only one account has registry publish access, which is a resilience concern for an independently owned package, although registry access alone does not establish actual maintenance capacity.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational backing to compensate for the concentrated maintainer base.

Release historycaution

The package is only 98 days old, with 12 releases and a median interval of about 6 hours 36 minutes; this shows active iteration but provides limited evidence of long-term maintenance and the rapid cadence may reflect an unsettled API.

Repo bus factorcaution

All 9 recent commits were made by one contributor, giving the project a complete single-contributor concentration and creating a material continuity risk for an independently owned repository.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anderson Alves

Direct Dependencies

DependencyLast ReleaseScore
setasign/fpdf
Version ^1.8
—
—
tecnickcom/tcpdf
Version *
—
—
symfony/var-dumper
Version *
—
—
nfephp-org/sped-common
Version ^5.1
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform