Healthy and reasonable to adopt. It has frequent recent releases, active work from two contributors, tests, and clear licensing; the main caveats are no security policy and minimal GitHub Actions permission declarations.
86%
Total Score
90
100
94
80
Only one account has registry publishing access, which is a modest administrative concentration; active repository work by two contributors provides some practical compensation.
Composer build tooling is present, but no security-scanning tools were detected; this is a transparency gap for a package handling invoice documents.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The only workflow does not declare top-level token permissions. Although no write permissions were explicitly requested, the default access level is less clear than it should be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdf Version 1.8.* | — | — |
setasign/fpdi Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.