The package has solid licensing, tests, documentation, and static analysis, with five releases in the last year. Maintenance has since gone quiet, and the workflows use six unpinned actions; the missing security policy is an additional transparency gap.
64%
Total Score
50
94
50
No commits or active maintainers were recorded in the last three months. With the last push tied to the December 2025 release, this indicates a meaningful period of maintenance inactivity.
The repository has one star, no forks, and one watcher. This is weak supporting evidence, though low popularity alone does not make a small maintained package unsafe.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
Both workflows were fully analyzed with no detected dangerous findings or untrusted checkouts, but all six action references are unpinned. The absence of top-level permissions is acceptable on its own, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.2 | — | — |
league/commonmark Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.