Package Health

handcraftedinthealps/goodby-csv

CSV import/export library

Latest 1.4.3PackagistPackagist

68%

Total Score

caution

Usable with caveats: no releases in 15 months and no recent repository activity suggest maintenance may be slowing.

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The package has four releases since November 2021, but none in the last 12 months and the latest was about 15 months ago, which points to slowing maintenance.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, reinforcing the concern raised by the lack of recent releases.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest process gap.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned, weakening build reproducibility and update control.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-49597
handcraftedinthealps/goodby-csv is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in versions 0.0.0 - 1.4.3.
0.0.0 - 1.4.3
Low

Package versions

Maintainers

reoring
suin
Handcrafted in the alps contributors

Direct Dependencies

DependencyLast ReleaseScore
symfony/polyfill-mbstring
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform