The package has minimal documentation and no visible security or testing practices. Its license and non-deprecated status help, but the project has shown no maintenance for years, so pinning this release carries substantial abandonment risk.
40%
Total Score
50
75
50
A README is present but only 76 characters long, while tests and a changelog are absent from the artifact; missing tests and changelog are normal packaging practice, but the limited consumer documentation is a real transparency gap.
The latest release was published in February 2022, and there were no releases in the following 12 months; this indicates prolonged release inactivity for a dependency.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the extended release gap and increasing abandonment risk.
Composer is used for builds, which is appropriate, but no security scanning tooling is present, leaving an additional maintenance and review gap for a package handling billing integrations.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a package that processes invoicing functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdf Version 1.8.4 | — | — |
afipsdk/afip.php Version 0.7.3 | — | — |
tecnickcom/tc-lib-barcode Version 1.17.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.