The MIT license, clear README, and matching source repository make the package straightforward to inspect. Its five runtime dependencies and lack of automated security scanning add maintenance overhead. The project is not archived and has a release note for this version, but ongoing validation appears limited.
56%
Total Score
33
50
72
83
The package has had no release in about four years despite eight total releases, indicating a long period without published maintenance. This is a meaningful abandonment concern, although the latest release is stable rather than a pre-release.
There were no commits and no active maintainers in the measured three-month period, matching the multi-year release gap. This materially increases the risk that defects or compatibility issues will remain unattended.
The package declares five runtime dependencies, including HTTP, barcode, PDF, and templating libraries. This is a moderate dependency surface that adds upkeep and transitive-change exposure.
Only one registry account can publish the package, leaving little apparent publishing redundancy. Because the linked project is user-owned, this is a genuine thin-maintainer concern rather than normal organization publishing hygiene.
The package and repository are both owned by the same individual user account, which supports repository identity but does not provide organizational backing or a broader continuity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
dompdf/dompdf Version ^1.2 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
picqer/php-barcode-generator Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.