It has a clear BSD-3-Clause license, a matching source repository, Composer tooling, and no install-time scripts. The workflow uses seven unpinned actions, adding avoidable build-integrity risk.
58%
Total Score
25
100
86
100
The package has 16 releases since 2012, but none in nearly four years; the latest release was in April 2022. This is strong evidence of stalled maintenance for a library dependency.
The repository had zero commits and zero active maintainers in the three months before collection, consistent with the long release gap. The repository is not archived, but there is no recent development activity to compensate.
There were no new or closed issues or pull requests in the past month, and no open issues or pull requests. This supports the conclusion that the project is inactive, although the small project scope may limit issue volume.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all seven action references are unpinned, so workflow dependencies can change without a commit review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.0 | — | — |
latte/latte Version ^2.10 | — | — |
nette/utils Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.