PHP library generating PDF files from UTF-8 encoded HTML
67%
Total Score
caution
No commits in the last three months despite a recent release, with all six CI actions unpinned.
The package runs a post-install-cmd lifecycle script, adding install-time behavior that consumers must trust. No other provided signal shows this is harmful, so it is a modest supply-chain and maintenance concern rather than a severe risk.
The package has 5 releases over about 3 years, with 1 release in the last 12 months and a median interval of about 169 days. This is slow but not abandonment by itself, especially with a recent latest release.
The repository recorded 0 commits and 0 active maintainers in the last three months. The release published on 2026-03-02 provides some compensating evidence, but the recent development silence remains a maintenance concern.
All 6 analyzed action references are unpinned, which weakens build reproducibility and action supply-chain control. The audit found no untrusted checkout, script injection, high-severity finding, or top-level write permission, which limits the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
setasign/fpdi Version ^2.1 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
myclabs/deep-copy Version ^1.7 | — | — |
paragonie/random_compat Version ^1.4|^2.0|^9.99.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.