Package Health

phpcfdi/cfditopdf

The package has a clear MIT license, release notes, repository tests, and no install-time scripts. Its organization-backed source remains identifiable, but the evidence does not show a broad maintenance base.

Latest v0.5.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. A release was published recently, which partly offsets but does not remove the concern about ongoing maintenance activity.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, but the project does provide security scanning through Sonar.

Workflow auditcaution

All 25 analyzed action references are unpinned, which weakens build reproducibility. The high-confidence template-injection finding is a workflow hygiene concern, while the low-confidence cache-poisoning finding carries little weight; no untrusted checkout or dangerous trigger was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Carlos C Soto

Direct Dependencies

DependencyLast ReleaseScore
league/plates
Version ^3.5
—
—
spipu/html2pdf
Version ^5.2.8
—
—
eclipxe/cfdiutils
Version ^3.0
—
—
phpcfdi/cfdi-cleaner
Version ^1.3.3
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform