It has a long release history, frequent recent releases, release notes, tests, and a security policy. All five workflow actions are unpinned, and the artifact’s detected GPL-3.0 text is broader than its LGPL declaration.
57%
Total Score
83
70
75
Packagist marks the entire package as abandoned, which is a substantial adoption and future-support concern even though releases continue.
A license file and LGPL-3.0-or-later declaration are present, but detected text also names GPL-3.0, which the declaration does not clearly cover.
All 15 recent commits came from one contributor, creating a significant continuity risk; organization backing provides some ability to hand off maintenance.
Both workflows were analyzed without injection or high-severity findings, and permissions are scoped, but all five referenced actions are unpinned, weakening build reproducibility.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10263 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. tecnick.com/tcpdf is vulnerable to Path Traversal in versions 6.0.013 - 6.9.0. | 6.0.013 - 6.9.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
tecnickcom/tc-lib-pdf Version ^8.78 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.