Package Health

horstoeko/zugferd-laravel

Usable with caveats: the release is licensed, documented, tested, and backed by an active-looking repository with sensible build and security tooling. However, the registry shows no release in about 18 months and the repository recorded no commits in the last three months, so verify ongoing compatibility before adopting it.

Latest v1.0.5PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

The package has six releases since September 2023, but none in about 18 months despite the repository being updated more recently. This weakens confidence in release maintenance and compatibility coverage.

Repo commit activitycaution

No commits or active maintainers were recorded in the last three months. This is a meaningful maintenance concern, although the non-archived repository and recent push provide some counterevidence.

Token permissionscaution

All four workflows lack top-level token permissions and none declares read-only permissions. Although no workflow requests top-level write access, explicitly constraining permissions would improve CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Erling

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^5|^6|^7
—
—
doctrine/dbal
Version ^2.9|^3|^4
—
—
illuminate/bus
Version >=5.7
—
—
illuminate/http
Version >=5.7
—
—
horstoeko/zugferd
Version ^1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform