Tests, a clear README, release notes, and a matching license support dependable use. The small project has little recent activity and its workflow references are not pinned, so maintenance and build-integrity risks remain.
65%
Total Score
50
100
86
75
The package has only 3 releases since November 2017, with no release in roughly 20 months and a median interval of about 3.6 years. This is a meaningful maintenance concern despite the recent 3.0.0 release.
There were no commits and no active maintainers in the last 3 months. Combined with the sparse release history, this points to limited ongoing maintenance capacity.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy. For a package that processes SEPA-related data, the absence reduces transparency around vulnerability reporting.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous sinks or audit findings. However, all 3 action references are unpinned, leaving build inputs less reproducible and more exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.