A single person made all 16 recent commits, leaving limited backup if maintenance stops. The workflow scopes permissions per job, but all five actions are unpinned.
76%
Total Score
67
100
50
The repository is owned by an individual user rather than an organization, so the single-maintainer and bus-factor concerns are not offset by visible organizational backing.
One contributor made all 16 commits in the last three months, creating a high single-maintainer dependency. The active commit rate offsets abandonment concerns but not the lack of maintenance redundancy.
The repository has no security policy. For a plugin that processes documents and exports PDFs, this weakens vulnerability-reporting transparency.
The workflow is fully analyzed, has no untrusted checkout or script-injection findings, and scopes permissions at job level. However, all five action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
carlos-meneses/laravel-mpdf Version ^2.1 | — | — |
picqer/php-barcode-generator Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.