Package Health

luchaninov/csv-file-loader

Usable with caveats: it is a small, well-documented package with tests, a clear license, and matching source code, but maintenance has recently gone quiet and depends on one maintainer. Suitable for use if its stable behavior meets your needs, with limited evidence of ongoing development.

Latest 1.10.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

The package has one registry maintainer. That is consistent with a small user-owned project, but it creates limited redundancy if that maintainer becomes unavailable.

Project backingcaution

The registry namespace and repository owner match, and the repository is owned by the same individual rather than an organization. This supports ownership consistency but offers limited institutional backing.

Release historycaution

The package has existed since 2015 and reached version 1.10.0, but it has had no releases in the last 12 months despite the latest release being in June 2025. This indicates a mature but currently quiet project.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Combined with no releases in the last year, this is evidence that ongoing maintenance is currently inactive.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. For a small library this is a transparency gap rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vladimir Luchaninov

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform