The MIT license and usable README make the package easier to evaluate and integrate. Its small codebase has no recent security policy or automated maintenance activity, leaving future compatibility and support uncertain.
42%
Total Score
25
83
50
The package has had no release in nearly five years and no releases in the last 12 months. Its four releases were concentrated in December 2021, so the historical burst does not offset the prolonged gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly five-year release gap. This is strong evidence of abandonment risk.
Only one registry maintainer is listed, leaving limited publishing and support capacity. The repository is user-owned rather than organization-backed, so there is no provided evidence of a broader team compensating for that thin base.
The linked repository has no security policy. For a library that handles tax-service credentials and API access, the absence reduces transparency around vulnerability reporting and support.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.0 | — | — |
ramsey/uuid Version ^3.7|^4.0 | — | — |
guzzlehttp/guzzle Version ^6.5|^7.0 | — | — |
kwn/number-to-words Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.