It has a clear README, tests, and a small dependency surface. Security scanning and a security policy are absent, leaving weak evidence of ongoing vulnerability response.
38%
Total Score
25
100
75
83
There were zero commits and zero active maintainers in the last three months, following the last push in July 2020. This materially raises abandonment risk for a dependency.
The repository is owned by an individual account rather than an organization, and the registry maintainer list contains one person. That is consistent with a small personal project but offers limited visible continuity if the maintainer stops working on it.
The package has only three releases, all clustered on 21 July 2020, and none in the last 12 months despite being over six years old. This is strong evidence of limited ongoing maintenance.
The repository has zero stars, forks, and watchers, providing no supporting evidence of a wider user or contributor base. Popularity is not required for health, but this removes a possible source of resilience.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a maintenance and vulnerability-response gap, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
box/spout Version ^3.1@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.