Usable with caveats: this is a licensed, tested, organization-backed package with a real release and no deprecation or workflow red flags. However, it has had no commits from active maintainers in the last three months, and its workflows lack explicit token permissions and security scanning.
74%
Total Score
67
100
88
88
The project has existed since 2013 with 26 releases, but only one release appeared in the last 12 months, indicating a slower recent cadence than its historical median of about 74 days.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may currently be paused despite the recent v8.0.0 release.
There are no open issues and only one open pull request, but no issues or pull requests were merged during the last month, providing limited evidence of current responsiveness.
Composer, Make, and four CI workflows are present, but no security scanning tools were detected, leaving a modest security-hygiene gap.
All four workflows omit top-level GitHub Actions token permissions, so their permissions are less explicit than recommended even though none declares top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.1.0 | — | — |
nette/http Version ^3.2.0 | — | — |
nette/application Version ^3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.