Healthy and reasonable to depend on, with frequent releases, tests, clear licensing, and an active organization-backed repository. Maintenance is concentrated in one contributor, and the repository lacks a security policy and security scanning, so review updates carefully.
82%
Total Score
83
50
94
80
The bundle declares 31 runtime dependencies, including database, Symfony, document generation, spreadsheet, and editor components. This is a substantial dependency surface and raises update and compatibility overhead, though it fits the bundle's broad functionality.
One contributor made 17 of 19 commits in the last 3 months, or about 89%, while two others made one each. The organization backing provides some handoff capacity, but current activity remains highly concentrated.
The project uses Make and Composer, but no security scanning tools were detected. The missing automated security checks reduce transparency around dependency and code risks.
No security policy was found in the repository. This is a transparency gap for reporting vulnerabilities, although it does not by itself indicate abandonment.
All 3 workflows lack top-level token permission declarations, even though none declares top-level write access. Explicit least-privilege settings would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.2 | — | — |
doctrine/orm Version ^2.6,>=2.6.3 || ^3.0 | — | — |
symfony/form Version ^7.0 || ^8.0 | — | — |
symfony/yaml Version ^7.0 || ^8.0 | — | — |
doctrine/dbal Version ^3.3 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.