The artifact carries a license file and release notes for this version, but the declared GPL-2.0-or-later conflicts with detected GPL-3.0. Its 136 runtime dependencies also increase upgrade and maintenance burden.
8%
Total Score
50
50
42
50
Packagist marks the entire package as abandoned and names ycloudyusa/yusaopeny as a replacement. This is a direct warning against taking a new dependency on this package.
The package has a substantial history of 84 releases, but it has had no releases in about 4 years 5 months. The long period without a release outweighs its earlier cadence.
There were zero commits and zero active maintainers in the last 3 months, consistent with the repository being archived and providing no evidence of ongoing maintenance.
The linked repository is archived, and its last push was about 4 years 3 months ago. An archived source repository indicates the project is no longer maintained.
The package declares 136 runtime dependencies, creating a broad upgrade and compatibility surface. The available maintenance evidence does not show active work to manage that burden.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^7 || v8.0.4 || ~v8.0.4 | — | — |
drupal/crop Version ^2 | — | — |
drupal/verf Version 1.0-beta7 || ^1.0 | — | — |
drupal/blazy Version ^2.4 | — | — |
drupal/confi Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.