Package Health

fond-of-oryx/invoice-extension

Stable versioning, MIT licensing, tests, and a minimal dependency set support adoption. The organization-backed repository is not archived, but maintenance has gone quiet and workflow references are unpinned. Missing documentation and a security policy add smaller transparency concerns.

Latest 2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

The package includes tests and the repository includes tests, which supports basic project maturity. The missing README reduces consumer guidance for an extension library, while the absent changelog is not a packaging concern by itself.

Release historycaution

The latest release was on January 23, 2023, with no releases in the last 12 months and only two releases overall. This is a meaningful maintenance concern, although the stable major version and non-deprecated status provide some context.

Repo commit activitycaution

There were zero commits and zero active maintainers in the three months measured. This is direct evidence of currently inactive maintenance and raises the risk of delayed fixes.

Repo toolingcaution

The repository uses Make and Composer, showing some build structure, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.

Security policycaution

No security policy was found in the linked repository. For a dependency intended for application integration, this weakens the project's vulnerability-reporting transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Rose
Jozsef Geng
Markus Nörenberg
Pascal Fischer

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform