Consumer documentation, release notes, and a small dependency surface are solid. Maintenance is recent but concentrated in one contributor, while the workflows use unpinned actions and the repository has no security scanning. The organization backing reduces, but does not remove, continuity risk.
76%
Total Score
83
100
94
50
All two recent commits came from one contributor, concentrating short-term maintenance capacity. Organization ownership provides some handoff potential, but no second recently active contributor is shown.
Composer build tooling is present, but no security scanning tools were detected. That weakens proactive maintenance hygiene without making the package unfit to use.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
All three workflows were analyzed cleanly and have no untrusted checkouts, script injection, or high-severity findings. However, all three action references are unpinned, which leaves the build exposed to action changes over time.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ~3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.