The breaking migration is documented, and the repository has tests, organization backing, and a security policy. Its modest adoption and small dependency surface reduce some risk, but ongoing maintenance should be confirmed before a long-term commitment.
62%
Total Score
75
100
93
83
The package has existed since 2018 with 28 releases, but only one release in the last 12 months indicates a slow release cadence. The recent v5.0.0 release provides some evidence that the project is not abandoned.
No commits and no active maintainers were observed during the last three months. Although a release exists within the last year, the lack of recent development activity is a meaningful maintenance concern.
All four workflows were analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all seven action references are unpinned, leaving workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.2.5 | — | — |
nette/schema Version ^1.3.5 | — | — |
thepay/api-client Version ^2.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.