Its dependency set is modest, and the package includes a README, changelog, and matching MIT license. With no commits in the last three months and no release for nearly seven years, relying on it carries substantial abandonment risk.
43%
Total Score
25
100
79
75
The package has only three releases, with no release in nearly seven years and a median interval of about 402 days. This is strong evidence of abandonment risk, despite the stable 1.0.3 version.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old latest release, this indicates inactive maintenance.
A single registry maintainer limits publishing continuity and bus-factor resilience. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader maintenance base.
The repository has six stars, two forks, and one watcher, providing little evidence of a broad user or contributor community. Popularity is supporting evidence, but this reinforces the maintenance concerns.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a hygiene gap rather than evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ^0.8.3 | — | — |
illuminate/support Version ^6.0 | — | — |
symfony/http-kernel Version ^4.3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.