Usable with caveats: the release is licensed, documented, tested, stable, and has no deprecation or install-time scripts. Maintenance activity is thin, with only one release in the last 12 months and no commits or active maintainers in the last three months.
62%
Total Score
0
100
89
75
There were zero commits and zero active maintainers in the last three months, which is the clearest abandonment concern in the available evidence.
The package has four releases over 674 days and only one release in the last 12 months, indicating a slow maintenance pace that matters for a framework integration.
The repository has only 3 stars, 1 fork, and 1 watcher, indicating limited external adoption and review; this is supporting caution rather than a verdict by itself.
No repository security policy is present, leaving the process for reporting and handling vulnerabilities unclear.
The one workflow does not declare top-level token permissions, so its GitHub Actions permissions are less explicit than recommended.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.