Package Health

gildonei/nfse-nacional

This release is usable and reasonably transparent: it has an MIT license with a license file, a substantial README, repository and artifact tests, a complete-looking source tree, six stable releases over 230 days, and no deprecation or archival status. However, the repository shows zero commits and zero active maintainers in the last three months despite the recent release, suggesting maintenance may have slowed or that release activity is not reflected in the measured commit window. The project is also maintained by a single user account, has no security policy or security-scanning tooling, and has a moderately broad runtime dependency set. Dependence is reasonable with normal maintenance and security review, but this is not a highly mature or strongly governed package.

Latest v1.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Twelve runtime dependencies, including HTTP, XML-signing, PDF, and framework utility packages, create meaningful dependency and update surface area. The profile is not severe on its own, but it warrants more review than a small self-contained library.

Maintainerscaution

Only one registry publishing maintainer is listed, leaving limited publishing redundancy. Because this is a user-owned project rather than an organization-backed repository, there is no provided compensating organizational context.

Project backingcaution

The repository is owned by a user account rather than an organization, so the project has limited demonstrated institutional backing. This reinforces the single-maintainer resilience concern.

Repo commit activitycaution

The repository records zero commits and zero active maintainers in the last three months, which conflicts with the recent release and push timestamp and leaves current maintenance capacity uncertain. This is a meaningful abandonment or release-process concern.

Repo popularitycaution

Eight stars, zero forks, and one watcher show limited external adoption and review. Popularity is supporting evidence only, so this lowers confidence in maturity modestly rather than making the package unfit.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gildonei M A Junior

Direct Dependencies

DependencyLast ReleaseScore
mpdf/mpdf
Version ^8.2
—
—
mpdf/qrcode
Version ^1.2
—
—
symfony/dotenv
Version ^7.4
—
—
guzzlehttp/guzzle
Version ^7.0
—
—
symfony/var-dumper
Version ^7.4
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform