The package includes tests, release notes for this version, and automated dependency auditing. Its MIT licensing and stable release history are reassuring, while workflow permissions and unpinned action references warrant routine review.
68%
Total Score
50
100
93
75
Tests and a release note for this exact version are positive evidence, but the six-character README provides almost no consumer guidance for a framework library.
The package and repository are owned by the same individual account, so there is no organizational backing shown to compensate for a narrow maintainer base.
The repository recorded no commits and no active maintainers during the last 3 months, which is a meaningful maintenance concern despite the recent push and earlier release activity.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
The single workflow analyzed cleanly with no dangerous triggers, untrusted checkouts, or audit findings, but it grants top-level write permissions and uses its only action reference unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^1.24 | — | — |
openspout/openspout Version ^4.13 | — | — |
claviska/simpleimage Version ^4.2.0 | — | — |
phpoffice/phpspreadsheet Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.