Clear documentation, licensing, repository tests, and release notes support straightforward integration. Workflow actions are mostly unpinned, creating a modest reproducibility risk despite the clean audit and active project tooling.
88%
Total Score
100
100
67
No repository security policy was found, which reduces disclosure transparency, although the active repository and Sonar scanning provide some compensating engineering practice.
The audit analyzed all six workflows with no injection or other findings, but 14 of 15 action references are unpinned, leaving a reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openspout/openspout Version ^4.24.5 || ^5.0 | — | — |
phpoffice/phpspreadsheet Version ^5.8.1 | — | — |
yajra/laravel-datatables-buttons Version ^13.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.