The package includes repository tests, a clear MIT license, and matching source ownership. Its small maintainer base, absent security policy, and unpinned workflow reference reduce confidence in long-term upkeep.
55%
Total Score
75
80
75
Only two releases exist, with the latest on January 1, 2024 and none in the last 12 months, indicating a long period without published maintenance.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the release gap and raising abandonment concerns.
The repository has zero stars, forks, and watchers. This is only supporting evidence, but it provides little external indication of adoption or community resilience.
No security policy is present in the repository, leaving vulnerability-reporting expectations unclear for a package that renders documents through a browser dependency.
The single workflow was fully analyzed with no reported audit findings and no risky triggers or broad permissions, but its one action reference is unpinned, which is a modest reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chrome-php/chrome Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.