No commits were recorded in the last three months, although the repository is not archived and this version has detailed release notes. MIT licensing, repository tests, and a security policy support adoption.
67%
Total Score
75
100
86
100
The package has only five releases across roughly nine years, with a median interval of about 16 months and one release in the last year. This indicates a slow maintenance cadence, though the latest release is recent.
No commits and no active maintainers were recorded in the last three months. This weakens evidence of ongoing maintenance, although the recent release and repository push provide some counterweight.
The repository uses Composer and Make, but no security-scanning tools were detected. This is a modest transparency and hygiene gap rather than a severe dependency risk.
All four workflows were analyzed without high-confidence findings or dangerous untrusted triggers, but all eight action references are unpinned. That leaves CI exposed to changing action contents and is a concrete supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/security Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.