Skip to content
CAI
Software that uses CAICheck a score

foliojs/pdfkit

59.1

Adequate · 2 October 2026

13.4k

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a JavaScript library for generating PDF documents, designed to function in both Node.js and browser environments. It provides core capabilities for creating structured documents, including text rendering, image embedding with format support, and form field creation. The library also features advanced layout tools such as table generation with accessibility support and integrates with modern bundlers like Webpack and Browserify for client-side usage.

How it got here

2011 — ES6 migration and dependency modernization

8 changes.

The project underwent a comprehensive migration from CoffeeScript to ES6, rewriting core libraries for font parsing, image handling, and mixins to improve browser compatibility and feature support. This effort was accompanied by modernizing the build infrastructure, switching to Yarn 4 and Vitest, and updating dependencies to require Node 20+ and support modern module systems.

2018–2021 — test coverage and browser examples

7 changes.

This period focused on expanding test coverage for image processing, PDF generation features, and visual regression testing to ensure robustness. It also introduced new examples and demos for accessibility, forms, and browser-based bundling with Browserify and Webpack 5.

2025–2026 — PDF rendering and infrastructure modernization

7 changes.

This period focused on enhancing PDF capabilities by introducing a new accessible table component and developing tools for efficient AFM font conversion. Concurrently, the project modernized its underlying infrastructure by migrating cryptography libraries to modern alternatives and updating the Yarn package manager.

Features

Add PDF table rendering with accessibility support

Introduces a new table component in \lib/table\ that renders structured PDF tables with support for row/column spanning, dynamic column widths (including star-based distribution), and cell styling (borders, padding, background colors). The implementation includes built-in accessibility features, generating PDF structure elements (Table, TR, TD/TH) with proper headers, scopes, and IDs to improve screen-reader compatibility.

lib/table · high confidence

Add webpack 5 example for browser-based PDF generation

Introduces a new webpack 5 example demonstrating how to bundle PdfKit for browser environments. The setup configures webpack to handle Node.js-specific modules (buffer, stream, zlib, util, assert) via fallbacks, disables the crypto module to reduce bundle size, and provides rules to inline static assets as base64 while loading lazy assets as URLs. The example includes a live editor that allows users to modify and preview PDF generation code in the browser.

examples/webpack · high confidence

Introduce AFM font conversion tools and build documentation

Adds a new set of tooling scripts and documentation for converting Adobe Font Metrics (AFM) files into JavaScript modules. The \tools/afm-converter.js\ script and its entry points (\convert-afm-runtime.js\, \convert-afm-parsed.js\) generate pre-parsed font data to avoid runtime parsing overhead, supporting both compact runtime formats and raw parsed schemas. The \tools/README.md\ documents these commands and the resulting data structures, while \asset-plugin.mjs\ and \binary-plugin.mjs\ provide Rollup utilities to embed source files and binary assets as base64 strings during the build process.

tools · high confidence

New Browserify demo with live code editing and local storage

Added a new browser-based demo in the examples/browserify directory that bundles PDFKit with Browserify. The demo features an interactive code editor (Ace) where users can modify PDF generation scripts and see the results update in real-time within an embedded iframe. It also persists the editor's content to the browser's local storage, allowing users to resume their work in subsequent sessions.

examples/browserify · high confidence

New and updated examples for accessibility, forms, and PDF features

The examples directory has been refreshed with new and updated scripts demonstrating key PDFKit capabilities. A new accessible-links example shows how to create PDF/UA compliant documents with properly nested link structure elements. The kitchen-sink-accessible example provides a comprehensive guide to building fully accessible PDFs with logical structure, alt text, and headings. Existing examples have been updated to showcase form field creation (including text, buttons, and lists), file attachments, PNG transparency and opacity options, horizontal text scaling, and spot color usage.

examples · high confidence

Architecture

Core library rewritten in ES6 with platform-specific entry points

The library has been rewritten in ES6, introducing separate entry points for browser and Node.js environments (\document.browser.js\ and \document.node.js\) to handle platform-specific dependencies like file system access and standard font loading. The core \PDFDocument\ class now extends Node's \Readable\ stream, and the codebase replaces Node \Buffer\ operations with \Uint8Array\-based helpers in \binary.js\ and \data.js\ to improve browser compatibility and reduce bundle size.

lib · high confidence

Behavioural changes

Added TypeScript definitions for Vitest custom matchers

Added a new type declaration file (types/jest.custom-matchers.d.ts) that provides ambient typings for custom Vitest matchers, specifically to enable TypeScript language server support for the new toContainChunk and toContainText matchers used in tests.

types · high confidence

Demo migrated from CoffeeScript to JavaScript

The demo application has been converted from CoffeeScript to JavaScript (ES6+). This change removes the \demo/test.coffee\ source file and the \demo/tiger.js\ data file, replacing them with their JavaScript equivalents to align with the project's broader language migration.

demo · high confidence

Major rewrite of mixins to ES6 and addition of new PDF features

The mixins in lib/mixins have been rewritten from CoffeeScript to ES6, introducing support for PDF tables, AcroForm options mapping, and enhanced text handling. The changes also include fixes for text wrapping, font cache collisions, and accessibility features, along with the addition of new methods for rounded rectangles and arc drawing.

lib/mixins · high confidence

Removal of legacy CoffeeScript font table parsers

The \lib/font/tables\ directory has been cleared of its previous CoffeeScript implementation files, specifically deleting the parsers for the \cmap\, \head\, \hhea\, \hmtx\, \maxp\, \name\, \os2\, and \post\ font tables. This change removes the old font parsing library from this location, aligning with the commit intent to switch to a new prototype-based approach for handling font data.

lib/font/tables · high confidence

Replace crypto-js with @noble/hashes and native APIs

The internal cryptography implementation in lib/crypto has been migrated from the crypto-js library to the @noble/hashes and @noble/ciphers packages, alongside the use of native browser APIs for random number generation. This change updates the underlying providers for AES (CBC/ECB), MD5, and SHA-256 hashing, as well as RC4 encryption, ensuring consistent build outputs and potentially improved performance or bundle size by using modern, tree-shakeable libraries.

lib/crypto · high confidence

Rewrite JPEG and PNG image parsers in JavaScript with improved EXIF and transparency support

The JPEG and PNG image parsers in lib/image have been rewritten from CoffeeScript to modern JavaScript (ES6+). The new JPEG parser now reads EXIF orientation data to correctly handle rotated images, and the PNG parser has been updated to properly support interlaced images, indexed transparency, and 16-bit alpha channels. These changes improve compatibility with various image formats and ensure images are embedded into PDFs with correct orientation and transparency.

lib/image · high confidence

Rewrite font parsing engine from CoffeeScript to ES6

The font parsing logic in lib/font has been completely rewritten from CoffeeScript to ES6. The new implementation introduces a dedicated AFMFont class for handling Adobe Font Metrics, which now includes support for kerning pairs and explicit WinAnsi encoding mappings. Standard fonts are now embedded using this new AFM-based engine, replacing the previous parsing approach. The old CoffeeScript font files (afm.coffee, dfont.coffee, directory.coffee, table.coffee, ttf.coffee) have been removed.

lib/font · high confidence

Test coverage

Added package resolution tests for Node and browser builds; Added tests for AFM font converter tool; Added unit tests for image processing; Added unit tests for the toContainChunk Jest matcher; Added visual regression tests for PDF rendering; Expanded unit test coverage for PDF generation features.

Dependencies

PDFKit v0.20.2: Modernized build, Node 20+ requirement, and new ESM/Node exports

This release updates the pdfkit library to version 0.20.2, shifting the minimum Node.js requirement to v20.0.0 and replacing the CoffeeScript source with native JavaScript. The package now supports modern module systems via new \exports\ and \imports\ fields, providing distinct entry points for Node.js (ESM and CommonJS) and browsers, including specific subpath exports for standard fonts. Dependency management has been modernized with \yarn\ v4, and runtime dependencies have been updated to use \fflate\ for compression, \@noble/hashes\ for hashing, and \fontkit\ for font handling. A new webpack example is included to demonstrate bundling with these updated dependencies.

(dependencies) · high confidence

Yarn updated to version 4.16.0

The bundled Yarn binary in .yarn/releases has been upgraded to version 4.16.0. This update brings the latest improvements and bug fixes from the Yarn team to the project's package management workflow.

.yarn · high confidence

Housekeeping

Initial repository setup and configuration scaffolding

This change establishes the foundational project configuration by introducing Yarn 4 as the package manager, replacing Jest with Vitest for testing, and configuring ESLint and Prettier for code quality. It also adds standard development scaffolding including .gitignore, .npmignore, CONTRIBUTING.md, and a Rollup build configuration, while updating the README to reflect the current JavaScript API and features.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 59 → 59 (+0.3)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 57 → 57 (+0.0)
  • Architecture 83 → 78 (-4.9)
  • Maturity 68 → 69 (+0.3)
  • Readiness 61 → 63 (+1.7)
  • Security 69 → 73 (+4.0)
  • Accessibility 55 → 55 (+0.0)
  • Performance 70 (new)

Resolved (6)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • Hotspot: docs/generate.js (docs/generate.js)
  • Off-boarding risk: anonymized user #1

New (18)

  • Documentation: no project overview (docs/table.md)
  • Documentation: no project overview (docs/text.md)
  • Documentation: no project overview (docs/vector.md)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • High CVE: [GHSA redacted] (yarn.lock)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (yarn.lock)
  • Medium vulnerability: [GHSA redacted] (yarn.lock)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): @noble/ciphers
  • Outdated (npm): @noble/hashes
  • Projects may be oversized for their cohesion
  • Repeated repair: lib/mixins/text.js (lib/mixins/text.js)

Changes since last survey

  • 3 commits — 1 feature/other, 2 fixes

By area

  • (root) — 3 commits

Notable commits

  • fix: Fix doc.list() throwing on a numbered or lettered list with align center or right (#1800)
  • fix: Fix wrapped text decorations counting character and word spacing twice (#1806)
  • change: Let the Node build be bundled: export registerStdFonts, resolve standard fonts and the ICC profile on first use (#1802)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

foliojs/pdfkit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 380631182e1d4f23889dc54cbafa1e0560802eca — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.