The package is licensed, tested, and has release notes, with an active-looking repository rather than an archived one. Its package-to-repository link is unclear, and the available maintenance evidence is stale for a dependency with many runtime dependencies.
45%
Total Score
50
50
69
75
The last registry release was in January 2021, about 5 years and 8 months before collection, with no releases in the previous 12 months. Its 100-release history shows past maturity but does not offset the prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old registry release, this is strong evidence of weak current maintenance.
The repository name does not match the package name and its README does not mention the package. That raises concern that the linked source may not actually correspond to this package, despite the repository otherwise containing related-looking source material.
The package declares 25 runtime dependencies, creating a broad maintenance surface for a release whose registry publication has been inactive for years. The signal does not show that these dependencies are unsafe, only that compatibility and upkeep may be harder.
There were no new or closed issues or pull requests in the measured month, while 12 issues and 5 pull requests remain open. This is consistent with limited current project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
itbz/fpdi Version 1.4.4 | — | — |
twig/twig Version ^1.26 | — | — |
league/csv Version ~7.0 | — | — |
guzzle/guzzle Version ^3.8.1 | — | — |
twbs/bootstrap Version 3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.