Package Health

lpdfio/lpdf

It includes tests, release notes, a license file, and a security policy. Frequent releases and organization ownership provide useful support, but the pre-1.0 version signals limited maturity.

Latest v0.22.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Repo bus factorcaution

All 21 recent commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is shown to reduce this concentration.

Repo toolingcaution

Composer is used for builds, but no security scanning tool was detected, leaving a modest security-process gap.

Version stabilitycaution

Version 0.22.0 is not a stable major release, so the API may still change even though it is not marked as a prerelease.

Workflow auditcaution

All workflows were analyzed successfully and avoid untrusted checkouts and script-injection triggers, but all six action references are unpinned and the release workflow has two high-confidence template-injection findings. These are workflow hygiene concerns rather than a standalone severe health failure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

lpdf.io

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
3 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform