This release appears usable and actively maintained, with 25 releases over about 5 months, a recent release, stable versioning, a non-archived repository, matching package documentation, tests, a changelog, and a clear MIT license. However, the project is still relatively young, all 24 recent commits come from one contributor, the package has a substantial runtime dependency surface, install and update lifecycle scripts require review, and there is no security policy or automated security scanning. Overall, it is a reasonable dependency for developers who can accept single-maintainer and security-process risk, but it is not yet a low-risk, broadly resilient project.
68%
Total Score
60
50
89
80
The package declares 24 runtime dependencies and only 1 development dependency. This broad runtime surface increases transitive maintenance and update exposure, even though the signal does not show any specifically problematic dependency.
The package runs post-install and post-update Composer scripts. These increase installation complexity and deserve review because they execute during dependency operations, although this signal alone does not establish an unsafe health verdict.
Only one account has registry publish access. This is a limited publishing resilience signal, and there is no organization backing shown to compensate for that concentration.
The repository owner is a user account rather than an organization, so the single-contributor and single-publisher concentration risks are not visibly offset by institutional backing.
One contributor made all 24 commits in the last 3 months, creating a severe concentration risk with no second active contributor or organization-owned repository to compensate.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.3 | — | — |
twig/twig Version ^3.0 | — | — |
filp/whoops Version ^2.18 | — | — |
simp/router Version ^1.1.5 | — | — |
react/socket Version ^1.17.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.