Package Health

devsconexa/mpdf

The package includes a license, README, release notes, tests in the repository, and a security policy. Its workflows use six unpinned actions, while repository activity was absent in the last three months and installation runs a post-install script.

Latest v8.2.6PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-install-cmd script, adding install-time behavior that consumers must trust. No provided signal shows that this script is dangerous, so this is a moderate hygiene concern rather than a severe risk.

Release historycaution

The package has 71 releases over about 2 years, but only one release in the last 12 months. The recent v8.2.6 release provides some evidence of continued publishing, but the overall cadence is now thin.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. The same-day release and repository push provide limited compensating evidence, but do not show sustained maintenance.

Repo popularitycaution

The repository has zero stars, zero watchers, and one fork, providing little external evidence of adoption or review. Popularity is supporting evidence only, so this modestly lowers confidence in project maturity rather than determining the verdict.

Workflow auditcaution

All six analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit was complete and found no untrusted checkouts, script injection, or high-severity findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Matěj Humpál
Ian Back

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
setasign/fpdi
Version ^2.1
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—
myclabs/deep-copy
Version ^1.7
—
—
paragonie/random_compat
Version ^1.4|^2.0|^9.99.99
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform