This is a mature, actively maintained and well-documented package: it has existed for over 10 years, has 39 releases including 3 in the last 12 months, is not deprecated, uses a stable release version, includes tests, a changelog, extensive documentation, and a matching organization-owned repository. The main concerns are that all seven recent commits came from one contributor, no repository security policy or security-scanning tooling was found, both workflows omit top-level token permissions, and installation uses a post-autoload-dump lifecycle script. These are meaningful transparency and operational risks, but they do not outweigh the package’s long release history, current repository activity, substantial scaffolding, and clear source-package correspondence.
82%
Total Score
80
100
94
70
The package uses a post-autoload-dump install lifecycle script. This adds execution during installation and merits review, although the signal does not show a broader set of install-time scripts or indicate malicious behavior.
Recent activity is fully concentrated in one contributor: one contributor made all 7 commits with a 100% share. Organization ownership provides some potential handoff capacity, but no second active contributor is shown in this signal.
Seven commits were made in the last 3 months, showing current activity, but all were produced by only one active maintainer.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is positive, while the missing security automation is a hygiene gap.
The repository has no SECURITY.md or equivalent security policy. This reduces vulnerability-reporting transparency, though it is a hygiene concern rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdi Version ^2.0 | — | — |
typo3/cms-core Version ^13.4 || ^14.3 | — | — |
tecnickcom/tcpdf Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.