It has clear licensing, a complete README, tests in the source repository, and read-only workflow permissions. The package is explicitly obsolete, with no registry releases since October 2018 and no recent commit activity, so pinning it creates maintenance risk.
45%
Total Score
50
78
50
The latest release was published in October 2018, and there have been no releases in the last 12 months despite the package being nearly ten years old. This is strong evidence that the release line is no longer actively maintained.
The repository had zero commits and zero active maintainers in the three months measured. This reinforces the release-history concern and raises abandonment risk for users of this version.
The repository has only 4 stars, 1 fork, and 3 watchers. Low popularity is supporting context rather than a verdict, but it provides little evidence of a broad maintenance community.
The repository uses Composer, but no security scanning tools were detected. The missing scanning tool is a maintenance and transparency gap, though it is not severe on its own.
No security policy was found in the repository. That makes vulnerability reporting less transparent for a library that handles document generation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.