The five-file package has a clear README and ordinary Composer dependencies, keeping integration straightforward. Its tiny project has no security scanning or policy, which limits transparency for future maintenance.
48%
Total Score
100
67
50
This is the only release, published nearly five years ago, with no releases in the last 12 months. That strongly limits evidence of active maintenance, although a small stable package may not need frequent releases.
Composer is used for builds, but no security-scanning tools are configured. That is a modest transparency and maintenance weakness for a package with little recent activity.
The repository is not archived, which is a positive, but its last push was nearly five years ago and is consistent with the stagnant release history.
The repository has no security policy. For this small package that is not severe on its own, but it leaves no documented path for reporting security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdf Version ^1.8 | — | — |
setasign/fpdi Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.