@Sinnbeck It's a wrapper for Dompdf, which doesn't have any external PDF libraries (https://github.com/dompdf/dompdf), so I think it can be chalked up to laziness, like you said.
@Tray2 Haha I'm quite new there. And this is not a software company at core. So I feel like it's more of a human relationship thing between the people there (like they're working together a long time so they're more like "friends" as long as it's not related to them). If I start calling out other people and I'm new there, I'll be the first to be fired just my feeling
You are not going to find something that lists current vulnerablities - at least, I certainly hope not. Any vulnerabilities are usually communicated off-line with the author and fixed without saying too much about what was wrong
@Snapey thanks. I really want answers from them now. I'm starting to feel more and more that they are just lazy. Blocking everything and goodbye. I am curious as to their reason of blocking it... Or... What is even the procedure they do to determine if a random zipped package is malicious