Package Health

creatissimo/mpdf

PHP library generating PDF files from UTF-8 encoded HTML

Latest v8.2.5PackagistPackagist

67%

Total Score

caution

No commits in the last three months despite a recent release, with all six CI actions unpinned.

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-install-cmd lifecycle script, adding install-time behavior that consumers must trust. No other provided signal shows this is harmful, so it is a modest supply-chain and maintenance concern rather than a severe risk.

Release historycaution

The package has 5 releases over about 3 years, with 1 release in the last 12 months and a median interval of about 169 days. This is slow but not abandonment by itself, especially with a recent latest release.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months. The release published on 2026-03-02 provides some compensating evidence, but the recent development silence remains a maintenance concern.

Workflow auditcaution

All 6 analyzed action references are unpinned, which weakens build reproducibility and action supply-chain control. The audit found no untrusted checkout, script injection, high-severity finding, or top-level write permission, which limits the concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Matěj Humpál
Ian Back

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
setasign/fpdi
Version ^2.1
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—
myclabs/deep-copy
Version ^1.7
—
—
paragonie/random_compat
Version ^1.4|^2.0|^9.99.99
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform