The project has one registry maintainer, no security policy, and no automated security scanning. It is licensed MIT, has a README and changelog, and is not deprecated or archived.
66%
Total Score
50
100
83
75
Only one account has registry publish access, leaving limited publishing redundancy. The linked repository is owned by the same individual account, which does not provide organizational backing to offset that concentration.
The repository owner is a user account rather than an organization, and no organizational backing is shown. That leaves the package dependent on an individual project owner.
The package has five releases over about three and a half years, with one release in the last 12 months and a median interval of about nine months. This indicates a maintained but slow release cadence.
There were no commits and no active maintainers in the last three months. Although the repository was pushed for the assessed release, the current lack of ongoing activity raises maintenance risk.
The repository has zero stars and forks and one watcher. This provides little evidence of broad community adoption, though popularity alone is not required for a small stable package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^7.3 | — | — |
symfony/mime Version ^7.3 | — | — |
setasign/fpdi Version ^2.6 | — | — |
symfony/config Version ^7.3 | — | — |
tecnickcom/tcpdf Version ^6.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.