Usable with caveats: the source repository is active and the release is not deprecated or archived, but the registry has had no release in the last 12 months. Maintenance is concentrated in one contributor, and the package carries a large runtime dependency set without a documented security policy.
72%
Total Score
67
50
88
75
The package declares 47 runtime dependencies, including many PHP extensions and related packages. This creates substantial integration and update surface area, though the broad dependency set may be expected for a full invoicing system.
The repository is owned by an individual user rather than an organization. That makes the concentrated contributor activity more significant because there is less visible organizational redundancy.
The package has 92 releases over roughly 3 years, but no registry release in the last 12 months despite a 4-day median interval historically. This suggests publication has slowed, although recent repository activity provides some compensation.
Two contributors were active in the last 3 months, but one made about 80% of the 88 commits. The second contributor provides some continuity, yet maintenance remains notably concentrated.
The repository uses Composer, but no security-scanning tools were detected. Build tooling supports reproducibility, while the absence of scanning leaves a security-maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version v3.1.0 | — | — |
phpunit/phpunit Version ^10.0.0 | — | — |
tomsgu/pdf-merger Version ^0.5.0 | — | — |
gamboa.martin/test Version ^5.0.0 | — | — |
spatie/dropbox-api Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.