The MIT license, signed Maven provenance, release notes, repository tests, and security tooling support dependable use. The project remains actively maintained despite concentrated ownership and workflow hygiene concerns.
72%
Total Score
67
100
100
100
The repository is owned by an individual rather than an organization, so the single-contributor concentration has no organizational handoff evidence to offset it.
All 31 recent commits came from one contributor, leaving maintenance highly dependent on a single person.
All 8 workflows were analyzed, with no untrusted checkout or script-injection trigger. However, 26 of 27 action references are unpinned, three workflows grant top-level write access, and high-confidence template-injection and secrets-inherit findings remain workflow hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-79918 fastcsv is vulnerable to Data Integrity Violation in versions 3.0.0 - 4.3.1. | 3.0.0 - 4.3.1 | Medium |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.