The project has useful documentation, tests, release notes, and a matching source repository. Its last release was over eight years ago, repository commits stopped about seven years ago, and no security policy or scanning is present.
43%
Total Score
25
81
67
The package has only 4 releases and none in the last 12 months; the latest release was over eight years ago. This is strong evidence of abandonment risk for a maintained integration library.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the old last push, this indicates that maintenance has effectively stopped.
An install-time post-root-package-install script is present. This adds some installation behavior to review, but the signal alone does not show unsafe or unusual actions.
The repository is owned by the same individual account associated with the package namespace, providing a consistent ownership link. It does not show organizational backing or a broader maintenance team.
Composer is used for builds, but no security scanning tools are reported. The missing scanning is a hygiene gap, while the build tooling itself is appropriate for this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version 0.6.* | — | — |
smarty/smarty Version ~3.1 | — | — |
league/flysystem Version ~1.0 | — | — |
vlucas/phpdotenv Version ~2.2 | — | — |
myclabs/deep-copy Version 1.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.