Library which simplifies bulk data loading into MySQL-compatible database engines using CSV collections.
43%
Total Score
unhealthy
Risky: no release since January 2020, with weak workflow and security maintenance signals.
The package has had no release for over six years: its latest release was January 21, 2020, and it has had no releases in the last 12 months. This is strong evidence of abandonment risk despite its stable version.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these low adoption signals provide little supporting evidence for long-term maintenance.
Composer build tooling is present, but no security-scanning tools were detected. That limits evidence of ongoing supply-chain and dependency hygiene.
The repository has no security policy. This is a transparency gap for a library that handles database loading, although it is less serious than evidence of active abandonment.
Both workflow action references are unpinned, and the audit found a high-confidence template-injection warning plus a script-injection count in the workflow. No dangerous trigger was reported, so this is a serious hygiene concern rather than a standalone critical finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
idct/php-csv-writer Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.