Its MIT license and focused README make the package easier to evaluate and adopt. Maintenance depends on one publisher, while the repository has no security policy or scanning and recorded no commits in the last three months.
62%
Total Score
50
50
94
50
The package declares 14 runtime dependencies, including several PHP extensions and PSR interfaces. This is a meaningful integration surface but not excessive for the broad set of database, import, middleware, and utility features described.
Only one account has registry publishing access. Because the repository is user-owned and recent releases exist, this indicates a limited bus factor rather than abandonment.
No commits or active maintainers were recorded during the last three months. The recent release provides some compensation, but the lack of current development activity still raises maintenance concern.
Composer is used for builds, but no security scanning tools were detected. This leaves a gap in automated security hygiene for a package handling authentication, database access, and file operations.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
psr/http-message Version ^1.0 | — | — |
ondrakoupil/tools Version ^1.2.7 | — | — |
aspera/xlsx-reader Version ^1.1 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.