The package has a minimal README, no repository tests, and no security policy. Its single release dates from July 2017, with no commits or releases since, leaving no evidence of ongoing maintenance.
12%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning against taking a new dependency on it.
There has been only one release, published in July 2017, and none in the following 9 years. That strongly indicates the package is abandoned rather than actively maintained.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long absence of releases. No provided signal shows current maintenance capacity.
The package includes a README and a GitHub release for this version, but the README says the library is still under development and the package has no tests or changelog. The missing tests are normal packaging practice, while the unfinished documentation limits transparency.
Composer is used for builds, but no security-scanning tool is detected. This is a secondary hygiene gap, and the stronger abandonment signals already dominate the assessment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
smalot/pdfparser Version ^0.10.0 | — | — |
doctrine/collections Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.