Healthy and actively maintained, with a long release history, frequent recent releases, strong repository activity, tests, and release notes. The main caveats are heavy reliance on one contributor and several install-time scripts, plus workflows without explicit top-level token permissions.
82%
Total Score
88
50
100
75
The application declares 88 runtime dependencies, creating a broad maintenance and transitive-dependency surface, although this is consistent with a full invoicing application.
Five install- and update-time lifecycle scripts run during package operations, increasing installation complexity and the amount of code executed automatically.
One contributor made 439 of 480 commits, or about 91%, which creates a significant continuity risk despite 14 contributors being active and the repository belonging to an organization.
Neither workflow declares top-level token permissions, leaving the default permission scope less explicit than recommended; no workflow requests top-level write access.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-3977 hillelcoren/invoice-ninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.3.35. | 0.0.0 - 5.3.35 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.14 | — | — |
laravel/ui Version ^4.0 | — | — |
league/csv Version ^9.6 | — | — |
nelexa/zip Version ^4.0 | — | — |
twilio/sdk Version ^6.40 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.