Usable with caveats: the package is licensed, tested, clearly linked to its source repository, and the repository is active and unarchived. The main concerns are that the latest registry release is over two years old, recent work is limited to two commits from one contributor, and the repository lacks a security policy and explicit workflow permissions.
72%
Total Score
75
50
94
75
The release declares 10 runtime dependencies, including several framework and project-specific packages, creating a moderately broad dependency surface and some additional upgrade coordination for consumers.
The package has 19 releases since November 2021, but it has had no registry release in the last 12 months and the latest release was January 12, 2024. Recent repository activity partly offsets this, but the release gap remains a maintenance concern for consumers of the published package.
All two recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some ability to hand maintenance off, so this is a concern rather than a severe risk.
The repository recorded two commits in the last three months, showing some current maintenance, but the activity level is low for a package with no recent registry release.
No security policy is present in the repository, leaving vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.1 | — | — |
latte/latte Version ^3.0 | — | — |
nette/caching Version ^3.2 | — | — |
drago-ex/utils Version ^1.0 | — | — |
nette/security Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.