This release appears to be a healthy dependency: it has a long release history dating to 2018, a current stable release, four releases in the last 12 months, an active non-archived organization-owned repository, recent commits from four contributors, tests, a matching repository with package references, and no install-time lifecycle scripts or registry deprecation. The main reservations are modest repository popularity, absence of a security policy, and no explicitly declared top-level workflow token permissions; these are transparency and hardening gaps rather than evidence of abandonment. The package is licensed under MIT and has a license file, while its small registry maintainer list is reasonably offset by organization backing and distributed recent repository activity.
86%
Total Score
100
100
89
80
The repository has modest adoption indicators with 9 stars and 8 forks; this is supporting evidence only and does not outweigh the stronger maintenance signals.
Composer build tooling is present, but no security scanning tools were detected; the lack of scanning is a hardening gap, though it is not evidence of abandonment.
No repository security policy was found, reducing vulnerability-reporting transparency and leaving a genuine but moderate hygiene gap.
The sole workflow has no top-level token permissions declaration. Although no top-level write permissions were observed, explicit least-privilege policy is absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pdffiller/qless-php Version ^3.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.