The MIT declaration, usable README, and Composer build provide basic transparency for adopters. A single maintainer, no security scanning, and a broad runtime dependency set leave limited evidence of ongoing care.
55%
Total Score
50
50
67
50
This is the only release, published about three years ago, with no releases in the last 12 months. That materially raises abandonment risk, although the package is not marked deprecated.
The package declares 10 runtime dependencies and no development dependencies, creating a relatively broad maintenance and compatibility surface for a small framework-style package. The collected signals do not show dependency controls that compensate for that complexity.
Only one registry account has publish access. For a user-owned project this is a thin operational base and increases continuity risk, though access records alone do not prove inactivity.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that has been inactive since late 2023. No newer release activity compensates for this gap.
The linked repository has no security policy, so users have no stated reporting or disclosure process. This is a transparency gap, but it is not severe enough to make the release unfit by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ^2.0 | — | — |
league/plates Version ^3.4.0 | — | — |
voku/html-min Version ^4.5 | — | — |
monolog/monolog Version ^2.9.1 | — | — |
scssphp/scssphp Version ^1.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.