This release appears reasonably safe to depend on from a maintenance and transparency perspective: it is not deprecated or archived, has a stable v2 release, a substantial README, changelog, tests, a complete-looking source tree, and a repository that clearly matches the package. Recent release activity is strong, but the project is young, has very low adoption, only two commits in the last three months, lacks repository security scanning and a security policy, and is maintained by a small user-owned project. These are meaningful due-diligence concerns rather than abandonment evidence, so the package is usable but should be adopted with normal dependency monitoring and review of its runtime dependencies.
78%
Total Score
60
50
89
90
The package has five runtime dependencies, including Laravel, PHPWord, Dompdf, and Intervention Image; this is a material dependency surface for a document-generation package, but not intrinsically excessive for its stated functionality.
Only one registry account has publish access. Because this is a user-owned project rather than organization-backed infrastructure, the narrow publishing base modestly increases continuity risk, though repository activity provides some compensation.
The repository owner is an individual user rather than an organization, so there is no organizational backing to compensate for the small maintainer base; however, the linked repository is active and package-specific.
Two commits from two active maintainers in the last three months show continuing activity, but the low volume indicates a small and lightly exercised maintenance stream.
There are no open issues or pull requests and no issue or pull-request activity in the last month. The clean tracker is not evidence of abandonment, but the absence of community activity limits external maintenance signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ^2.0 | — | — |
phpoffice/phpword Version ^1.2 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
intervention/image Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.