The package is licensed, has repository tests, and provides release notes for this version. No commits were recorded in the measured three-month window, while all 8 workflow actions are unpinned. Organization backing and a recent release reduce, but do not remove, the maintenance and reproducibility concerns.
68%
Total Score
75
94
75
No commits or active maintainers were recorded during the measured three-month window. That weakens evidence of ongoing maintenance, even though the repository is not archived.
The repository uses Composer and Make, showing basic build tooling, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
All four workflows were analyzed without high- or medium-severity findings and have no untrusted checkouts or script injections. However, all 8 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.1.8 | — | — |
nette/http Version ^3.2.3 | — | — |
latte/latte Version ^3.0 | — | — |
nette/application Version ^3.1.14 | — | — |
contributte/api-router Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.