The README gives basic installation and configuration guidance, and the package has no install-time scripts. Stable versioning and an unarchived repository help, but limited security and testing evidence reduces transparency.
38%
Total Score
0
75
83
The package has had only two releases, both in March 2019, with no release in roughly seven years. This strongly indicates abandonment risk for a maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited ongoing maintenance.
No declared license, license file, or detected repository license was found. That leaves the legal terms for using this dependency unclear.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling was found. For an inactive package, that weakens ongoing transparency.
The repository has no security policy. This is a transparency gap, although the package's small scope and lack of recent activity limit how much this changes the overall assessment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^2.4 | — | — |
nette/http Version ^2.4 | — | — |
nette/neon Version >=2.4 | — | — |
latte/latte Version >=2.4 | — | — |
kdyby/console Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.