Clear documentation, tests, licensing, and regular releases support adoption. The workflow leaves all three actions unpinned, and the project has no security policy, increasing maintenance and build-transparency concerns.
72%
Total Score
75
50
93
50
Six runtime dependencies make the package a relatively deep wrapper, increasing transitive maintenance exposure compared with a self-contained library, though the dependencies fit its stated invoice-format integrations.
All 3 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single active individual despite organization ownership.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in an invoice-processing library.
Version 0.3.2 is not marked prerelease, but the package remains below 1.0, so its API may still change more than a mature major release.
The workflow scopes permissions read-only and has no dangerous audit findings, but all 3 action references are unpinned, leaving build inputs less reproducible and more exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/metadata Version 2.8.0 | — | — |
atgp/factur-x Version ^1.0 | — | — |
jms/serializer Version 3.28.0 | — | — |
milo/schematron Version dev-master | — | — |
josemmo/einvoicing Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.