Healthy and usable for production, with a thin maintenance base as the main caveat. The package has a long release history, recent releases, active commits, clear licensing, tests in the repository, and no deprecation or dangerous workflow findings; most recent commits come from one of two contributors.
78%
Total Score
67
100
89
88
The registry namespace and repository are owned by a user account rather than an organization. Recent release and commit activity compensate for the lack of organizational backing, but succession capacity is less clear.
One contributor made 11 of the 12 recent commits, leaving maintenance heavily concentrated despite a second active contributor. This is a real continuity risk for a user-owned repository.
The repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but does not outweigh the strong release and maintenance signals.
The repository uses Composer build tooling but reports no security scanning tools. The missing scanning is a transparency gap, although other workflow and security-policy signals provide some compensation.
The only workflow lacks a top-level permissions declaration. No write permissions were observed, but explicitly limiting token permissions would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
masterminds/html5 Version ^2.0 | — | — |
dompdf/php-svg-lib Version ^1.0.0 | — | — |
dompdf/php-font-lib Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.