The repository has no security policy, and its only workflow uses an unpinned action. MIT licensing, tests, release notes, and organization backing provide useful transparency despite the limited recent activity.
62%
Total Score
63
100
78
75
There were zero commits and zero active maintainers in the last three months. Combined with the July 2024 latest release, this is the clearest sign that maintenance has stalled.
The package has 50 releases since 2014, but none in the last two years; the latest release was in July 2024. This established history is positive, while the current pause raises maintenance concern.
There is one open issue and one open pull request, but no issues or pull requests were created or closed in the last month, consistent with limited current activity.
The repository name does not match the package name and its README does not mention the package, creating uncertainty that the linked repository is the package's true source.
The repository has only 6 stars and 6 forks, indicating a small user base. Popularity is supporting evidence, so this is a minor concern rather than a decisive risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.2 | — | — |
keboola/php-temp Version ^2.0 | — | — |
keboola/php-utils Version ^4.1 | — | — |
keboola/php-csvtable Version ~2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.