Usable with caveats: the release is actively developed, documented, licensed, and backed by an organization, but it is only one day old and maintenance is concentrated in one contributor. Review its pull-request workflows before adopting it, since two use elevated pull-request triggers and one checks out untrusted code.
68%
Total Score
88
100
89
80
Two workflows use pull_request_target and one checks out untrusted code, creating avoidable CI exposure. No script injection was detected, but these workflow patterns still warrant review before trusting the repository's automation.
The package is only 1 day old with two releases, so there is not yet enough history to demonstrate long-term maintenance or release stability.
Two contributors were active, but one produced 86.7% of the last three months' commits. Organization backing provides some handoff capacity, yet practical maintenance remains concentrated.
The repository uses Composer build tooling, but no security-scanning tool was detected. The build setup is present, while security-process transparency is limited.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.7 | — | — |
nyholm/psr7 Version ^1.5 | — | — |
jms/serializer Version ^3.17 | — | — |
pimcore/pimcore Version ^2026.2 | — | — |
openspout/openspout Version ^4.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.