Healthy and suitable to depend on. It has a long release history, frequent recent releases, active work from multiple contributors, and a matching, well-maintained source repository. The only notable gap is the absence of a documented security policy.
94%
Total Score
100
100
100
90
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting expectations undocumented; this is a transparency gap, though active releases and Dependabot provide compensating maintenance evidence.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-255817 phpoffice/phpspreadsheet is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.8.0, 3.3.0 - 3.10.6, 2.2.0 - 2.4.6, 2.0.0 - 2.1.17 and 0.0.1 - 1.30.5. | 0.0.1 - 1.30.52.0.0 - 2.1.172.2.0 - 2.4.6 +2 more | High |
AIKIDO-2026-411546 phpoffice/phpspreadsheet is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.8.0, 3.3.0 - 3.10.6, 2.2.0 - 2.4.6, 2.0.0 - 2.1.17 and 0.0.1 - 1.30.5. | 0.0.1 - 1.30.52.0.0 - 2.1.172.2.0 - 2.4.6 +2 more | High |
AIKIDO-2026-826397 phpoffice/phpspreadsheet is vulnerable to Server-Side Request Forgery (SSRF) in versions 4.0.0 - 5.8.0, 3.3.0 - 3.10.6, 2.2.0 - 2.4.6, 2.0.0 - 2.1.17 and 0.0.1 - 1.30.5. | 0.0.1 - 1.30.52.0.0 - 2.1.172.2.0 - 2.4.6 +2 more | High |
CVE-2026-45034 phpoffice/phpspreadsheet is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.30.4. | 0.0.0 - 1.30.4 | Critical |
CVE-2026-40296 phpoffice/phpspreadsheet is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 5.6.0, 3.3.0 - 3.10.4, 2.2.0 - 2.4.4, 2.0.0 - 2.1.15 and 0.0.0 - 1.30.3. | 0.0.0 - 1.30.32.0.0 - 2.1.152.2.0 - 2.4.4 +2 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
composer/pcre Version ^1||^2||^3 | — | — |
markbaker/matrix Version ^3.0 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
markbaker/complex Version ^3.0 | — | — |
maennchen/zipstream-php Version ^2.1 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.