Tests, a clear license, and organization backing improve confidence. Work is concentrated in one contributor, security scanning and a security policy are absent, and all seven workflow actions are unpinned.
68%
Total Score
88
100
89
67
The package is nearly two years old and has had no release in the last 12 months, which raises release-maintenance concerns. However, the linked repository has recent commit activity, partly offsetting the stale registry cadence.
One contributor made 31 of 33 recent commits, leaving maintenance heavily concentrated despite a second active contributor. Organization backing provides some handoff capacity but does not remove the concentration risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a useful repository safeguard absent.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, and neither grants top-level write access. However, all seven action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tecnickcom/tcpdf Version ~6.7.5 | — | — |
phpseclib/phpseclib Version ^2.0.47 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.