Usable with caveats: the repository is active, tested, licensed, and recently released, but the project has only two releases and all recent commits come from one contributor. Review its small maintenance base before making it a critical dependency.
72%
Total Score
83
100
81
83
Only two releases exist across about 2 years and 8 months, with one release in the last 12 months. This is a thin release history, though the recent release shows the project is not abandoned.
All 34 recent commits came from one contributor, leaving a concentrated maintenance base. Organization ownership provides some ability to hand off maintenance, but no second active contributor is shown.
The project uses Make and Composer, but no security-scanning tool was detected. This is a transparency gap rather than evidence that the package is unsafe.
All four workflows omit top-level token permissions, so their default permissions are less explicit than desirable. No workflow requests top-level write access, which limits the concern.
Version 0.2.0 is not a stable major release, so the public API may still change; it is nevertheless a normal release rather than a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/utils Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.