The package includes detailed documentation, tests, MIT licensing, and a repository owned by an organization. No security policy or automated security scanning is present, limiting maintenance assurance.
68%
Total Score
83
100
86
75
The package is only 45 days old, with all 13 releases occurring in that period and a median interval of about 2 hours; this shows activity but leaves little evidence of long-term stability.
All 16 recent commits came from one contributor, creating concentration risk; organization ownership provides some capacity to hand maintenance off, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tools were detected, leaving an avoidable assurance gap for a package that processes downloaded data files.
The repository has no security policy, so there is no documented path for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
openspout/openspout Version ^4.24 | — | — |
spatie/laravel-data Version ^4.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.