The repository has no tests or security policy, although it includes a clear README, a matching source repository, and organization backing. Its narrow dependency set and inactive risk controls leave less evidence than an established package.
58%
Total Score
75
100
88
75
The package was first released less than a day ago and already has 22 releases, with a median interval of only a few minutes. This shows active publishing but provides no meaningful long-term maintenance record.
No commits or active maintainers were recorded in the previous three months. Because the repository is less than a day old, this is mainly a lack of maintenance history rather than evidence of abandonment.
Composer is used as the build tool, but no security-scanning tool was detected. That leaves a meaningful supply-chain hygiene gap for a package intended to be installed as a dependency.
The repository has no security policy, giving users no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
easybill/zugferd-php Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.