Risky to adopt: this small Composer plugin has had no release or repository activity since January 2016. Its coherent package contents and stable version help, but the decade-long inactivity, minimal documentation, and repository/package identity mismatch make maintenance and provenance concerns substantial.
38%
Total Score
50
100
50
90
The package has 4 releases, but its latest release was over 10 years ago and it has had no releases in the last 12 months. That long period without updates is a strong abandonment concern for a dependency.
The repository name does not match the package name and its README does not mention the package. That raises a provenance concern because the linked repository may not clearly establish ownership of this release.
The linked repository is not formally archived, but it was last pushed in January 2016, matching the stale release history and indicating that the project is effectively inactive.
Only one registry account has publish access. That is a modest resilience concern for an individually owned package, and the long inactivity provides no evidence of an active backup maintainer.
The artifact includes a README, but it is only 14 characters and provides essentially no usage guidance; missing tests and changelog files are normal for a published artifact and are not counted against it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ^0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.