The source repository has tests, release notes, an MIT license, and organization backing. Its workflow audit found all eight actions unpinned and a high-confidence secrets-inherit issue.
38%
Total Score
67
79
75
Packagist marks the package abandoned at package scope and names contributte/codeception as its replacement, making this release a poor default dependency choice.
The package has 37 releases since 2014, but its latest registry release was about five years ago and there were no releases in the last 12 months. Recent repository activity partly offsets the staleness but not the release gap.
All recent commits came from one contributor, leaving no demonstrated short-term contributor redundancy. Organization backing provides some handoff capacity but does not remove the concentration concern.
Only one commit from one active maintainer was recorded in the last three months. That is some activity, but it indicates a very low current maintenance pace.
All 8 of 8 action references are unpinned, and the audit found a high-confidence medium-severity secrets-inherit issue in coverage.yml. No dangerous trigger or untrusted checkout was detected, but the workflow hygiene is weak.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.0 | — | — |
nette/http Version ^3.0.3 | — | — |
nette/utils Version ^3.0 | — | — |
nette/bootstrap Version ^3.0 | — | — |
codeception/codeception Version ^4.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.