Strong tests, a detailed README, and matching MIT licensing make the package transparent and practical to evaluate. Maintenance is thin: all three releases arrived within about a day, followed by 209 days without a release and no commits in the last three months. A single maintainer and no security policy add longer-term continuity concerns.
57%
Total Score
50
83
50
Only one registry account can publish the package. The repository is user-owned rather than organization-backed, so there is little visible redundancy if that maintainer stops responding.
The package is 209 days old with three releases, all clustered within about a day; the latest release was followed by a long period without another release. That burst does not demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, which is meaningful evidence of currently inactive development for a young package.
The repository has 9 stars, 2 forks, and no watchers. This offers little community support evidence, although low popularity alone is not a health verdict.
Composer build tooling is present, but no security-scanning tool is configured. This is a hygiene gap rather than evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
smalot/pdfparser Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
phpoffice/phpword Version ^1.4 | — | — |
intervention/image-laravel Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.