The repository has tests, release notes, an organization behind it, and a documented security policy. Workflow references are not pinned, so build reproducibility is weaker than the otherwise solid project structure.
58%
Total Score
67
88
83
The package has 15 releases since November 2018, but none in the last 12 months; the latest registry release was about 18 months ago. This is a meaningful maintenance concern, though the repository remains active enough to avoid an abandonment verdict on its own.
The repository recorded zero commits and zero active maintainers in the last three months. That is the clearest abandonment concern, although the repository is not archived.
There were no new or closed issues or pull requests in the last month, despite two open issues and five open pull requests. This supports a caution about limited recent project activity.
The project uses Composer and Make, but no security scanning tools were detected. This is a modest repository-hygiene gap rather than evidence that the package is unsafe.
All four workflows were analyzed with no untrusted checkouts, script injection, or audit findings, and none grants top-level write access. However, all 8 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.1.8 | — | — |
nette/http Version ^3.2.3 | — | — |
latte/latte Version ^3.0.12 | — | — |
nette/utils Version ^4.0.3 | — | — |
nette/application Version ^3.1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.