Recent releases, a security policy, and active repository work provide useful support. The package is still marked abandoned, and the repository does not identify or mention this package, so pinning the replacement is safer.
45%
Total Score
75
100
75
83
The package is deprecated at package scope and points to basoro/mlite as its replacement. This is a major adoption risk even though the replacement repository is active.
The artifact includes license files, but the manifest declares MIT while the detected license is GPL-3.0. This mismatch creates a real licensing clarification risk.
The registry and repository are owned by the same individual account, not an organization. This provides direct ownership alignment but limited organizational handoff capacity.
One contributor made about 94% of the 35 recent commits, leaving maintenance highly concentrated. A second active contributor provides limited compensation, so continuity risk remains.
The repository name does not match basoro/khanza-lite and its README does not mention the package. That raises a genuine concern that the package may be published from a related but different project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.2 | — | — |
mpdf/qrcode Version ^1.2 | — | — |
halaxa/json-machine Version ^1.2 | — | — |
phpmailer/phpmailer Version ^6.9.1 | — | — |
phpseclib/phpseclib Version ~3.0.36 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.