Package Health

horde/pdf

Tests, a changelog, and detailed release notes provide useful project transparency. The prerelease status, sparse release history, and no commits or issue activity in the last three months make ongoing maintenance uncertain.

Latest v3.0.0RC1PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is about 2 years and 9 months old with eight releases, but only two releases in the last 12 months and a zero-day median interval suggest a sparse and uneven cadence.

Repo commit activitycaution

There were zero commits and zero active maintainers during the last three months. Although the recent release shows the project has not vanished, this is a meaningful maintenance warning.

Repo issue activitycaution

The repository has 10 open issues but no new or closed issues and no merged pull requests in the last three months. That lack of visible issue movement weakens evidence of active maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and assurance gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For a library that implements PDF parsing and encryption-related functionality, the missing reporting guidance reduces maintenance transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ralf Lang
Jan Schneider
Mike Naberezny
Chuck Hagenbuch

Direct Dependencies

DependencyLast ReleaseScore
horde/util
Version ^3 || dev-FRAMEWORK_6_0
—
—
horde/exception
Version ^3 || dev-FRAMEWORK_6_0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform