The package has clear documentation, repository tests, release notes, and a matching MIT-licensed source repository. Its single-contributor maintenance and entirely unpinned workflow actions leave limited safety margin.
66%
Total Score
50
50
83
100
Six runtime dependencies, including PDF, barcode, and Faker-related packages, create a meaningful dependency surface but are consistent with the library's stated functionality.
Only one registry account has publish access. Because the repository is user-owned rather than organization-backed, this leaves limited publishing redundancy.
The repository is owned by the same individual namespace as the package and is not organization-backed, so there is no visible institutional maintenance buffer.
The package has had no registry releases in the last 12 months, despite six releases early in its 585-day lifetime; this indicates stalled delivery for a library dependency.
All recent commits came from one contributor, so a maintainer outage could leave fixes and releases blocked; no organization backing is shown to compensate for this concentration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.0|^8.1 | — | — |
fakerphp/faker Version ^1.0 | — | — |
cable8mm/stub-template Version ^1.0 | — | — |
picqer/php-barcode-generator Version ^3.2 | — | — |
mbezhanov/faker-provider-collection Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.