Usable with caveats: the package is licensed, documented, tested in its repository, and not archived, but it has had no release or commit activity for over two years. Its single-maintainer project also lacks security scanning and a security policy, so ongoing support is uncertain.
58%
Total Score
38
50
78
80
There were zero commits and zero active maintainers in the last three months, reinforcing that development appears to have stopped for more than two years.
Eleven runtime dependencies, including AWS, OpenAI, PDF, and Laravel-related packages, create a relatively broad dependency surface for a small package and increase compatibility and maintenance burden.
The package runs a post-autoload-dump install-time script. This is a review point because lifecycle scripts execute during installation, although no provided signal shows that this script is malicious or unusually dangerous.
One registry account has publish access. Because the repository is user-owned rather than organization-backed, this represents a limited publishing and continuity base.
The registry namespace and repository owner match, which supports that the linked repository belongs to this package. The owner is an individual rather than an organization, so continuity depends on a small project base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jstewmc/rtf Version ^0.5.2 | — | — |
aws/aws-sdk-php Version ^3.281 | — | — |
smalot/pdfparser Version * | — | — |
openai-php/laravel Version ^0.10.1 | — | — |
symfony/dom-crawler Version ^7.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.