Package Health

jmleroux/pdf-merger

The package has a clear README, tests, an MIT license, and no install-time scripts. Its small, inactive project offers little evidence of ongoing fixes, so pinning it carries substantial maintenance risk.

Latest v2.0.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

Only two releases were published, both in April 2020, with none in the last 12 months; the package has had no new release for over six years. This is strong evidence of abandonment risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the last repository push being over six years ago. This materially increases abandonment and unpatched-defect risk.

Dependency profilecaution

Five runtime dependencies, including three alternative PDF libraries, create a relatively broad dependency surface for a small merger package. The alternatives are directly related to the documented functionality, so this is only a modest concern.

Project backingcaution

The registry namespace and repository are owned by the same individual account, providing consistent ownership context but no organizational backing to compensate for the thin activity record.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 1 watcher, indicating very limited community visibility or external validation. Small packages can still be healthy, but this provides little compensating evidence for inactivity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Paul Clegg
JM Leroux

Direct Dependencies

DependencyLast ReleaseScore
setasign/fpdf
Version ^1.8
setasign/fpdi
Version ^2.3
setasign/tfpdf
Version ^1.31
tecnickcom/tcpdf
Version ^6.3

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform