This is a mature, actively maintained release with a history since 2015, 78 releases, nine releases in the last 12 months, a stable non-prerelease version, and a repository that is current, unarchived, correctly associated with the package, and backed by an organization. The main concerns are the absence of repository tests despite PHPUnit workflow evidence, no security policy, and unspecified GitHub Actions token permissions; these are meaningful transparency and hardening gaps but do not outweigh the strong release and maintenance activity. The package appears reasonable to depend on, with normal supply-chain review of its three runtime dependencies still warranted.
84%
Total Score
88
100
88
80
A README and changelog are present and GitHub Releases are used, which supports release transparency. However, neither the artifact nor the repository contains tests, despite the package being a substantial application plugin, leaving a genuine quality-assurance gap.
There is some recent issue activity, with one new issue in the last month, but no issues or pull requests were closed during that period and nine issues remain open. This is a modest maintenance concern, not evidence of abandonment given the recent commits and releases.
Composer is used as a build tool, providing standard dependency and packaging structure. No security scanning tools were detected, which limits automated security hygiene but is not by itself a severe health issue.
The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations, creating a genuine but non-critical maintenance concern.
All three workflows lack top-level token permission declarations. Although none declares top-level write access, explicitly constraining permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ~3.1.0 | — | — |
kigkonsult/icalcreator Version ^2.41 | — | — |
npm-asset/fullcalendar Version ~6.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.