PHP library generating PDF files from UTF-8 encoded HTML
42%
Total Score
79
50
The package has 58 releases, but its latest release was in March 2022 and it has had no releases in the last 12 months. That prolonged inactivity is a substantial abandonment concern for a library dependency.
A post-install-cmd script runs during installation, increasing installation complexity and the amount of package behavior that must remain maintained. No provided signal shows that this script is harmful, so this is a hygiene concern rather than a severe risk.
The linked repository is not archived, which is a positive counterpoint, but its last push was also in March 2022 and does not offset the stale release history.
The repository has no security policy or security-scanning tooling. This weakens vulnerability-reporting and maintenance transparency, although it does not by itself show that the package is unsafe.
All 6 analyzed action references are unpinned, so workflow dependencies can change without a reviewed package release. The audit found no untrusted checkouts, injection sinks, dangerous triggers, or high-severity findings, which limits this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 | — | — |
setasign/fpdi Version ^2.1 | — | — |
myclabs/deep-copy Version ^1.7 | — | — |
paragonie/random_compat Version ^1.4|^2.0|^9.99.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.