The package includes a README, tests, an MIT declaration, and no install-time scripts. Its tiny, single-maintainer footprint offers little evidence of ongoing support for future fixes.
42%
Total Score
50
75
100
Only one registry publishing account is listed, leaving limited visible publishing capacity. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader support team.
This is the only release, published nearly six years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency needing future maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but that does not compensate for absent recent activity.
The repository has 2 stars, 1 fork, and 1 watcher, providing little community evidence to offset the lack of recent maintenance. Low popularity alone is not disqualifying for a small package.
Composer is used for the build and dependency workflow, but no security scanning tool is configured. This is a modest transparency and maintenance gap for a package with no recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdf Version 1.8.* | — | — |
setasign/fpdi Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.