Package Health

einhasad/mpdf-light

Lightweight mPDF fork without font subsetting

Latest v8.2.4PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

A post-install-cmd script runs during installation. This adds some installation complexity and supply-chain exposure, although the available signals do not show that it is harmful.

Maintainerscaution

Only one registry account has publish access, which creates a thin publishing base. The repository is organization-owned, making the short registry list less concerning than it would be for an independently owned project.

Release historycaution

The package has only one release, published about 23 months ago, with no releases in the last 12 months. That limited history and lack of ongoing releases reduce confidence in maintenance.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is the strongest evidence of reduced maintenance capacity.

Repo popularitycaution

The repository has one star, no forks, and no watchers. Popularity is only supporting evidence, but these very low figures provide little evidence of a broad user or contributor community.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dmytro Popov

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
setasign/fpdi
Version ^2.1
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—
myclabs/deep-copy
Version ^1.7
—
—
paragonie/random_compat
Version ^1.4|^2.0|^9.99.99
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform