The package has a clear README, matching source repository, MIT licensing, and release notes for this version. Testing and security transparency are limited, while repository activity has been quiet since the latest release; adopt with ordinary maintenance caution.
68%
Total Score
50
100
83
75
The repository is owned by a user account rather than an organization, so the small registry maintainer base is not offset by visible organizational backing.
The package has released 10 versions over about 2.5 years, including one release in the last 12 months. That shows ongoing publication, though the recent cadence is limited.
The repository recorded no commits and no active maintainers in the last three months. The recent release partly compensates for this, but current maintenance capacity remains unclear.
The repository has no stars, forks, or watchers. This provides little evidence of external adoption, but popularity is supporting evidence and does not outweigh the package's direct maintenance signals.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency and maintenance gap for a dependency package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.2.5 | — | — |
symfony/config Version ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^7.0 || ^8.0 | — | — |
symfony/http-foundation Version ^7.0 || ^8.0 | — | — |
symfony/framework-bundle Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.