Clear documentation, tests, and release notes make integration straightforward. Organization backing and security tooling help offset the small recent contributor base, but workflow pinning and policy coverage remain limited.
74%
Total Score
75
100
100
83
All one recent commit came from a single contributor, leaving no demonstrated second active contributor. Organization ownership provides some handoff capacity but does not remove the observed concentration.
Only one commit was recorded in the last three months, so recent development activity is thin. The current release and recent push provide some compensation, but not enough to remove the maintenance caveat.
No repository security policy was found. For a small library this is a transparency gap, though the presence of GitGuardian scanning partially offsets the concern.
All three workflows were analyzed without failed files, dangerous triggers, injection findings, or excessive top-level permissions. However, all 9 action references are unpinned, which is a workflow supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.2 | — | — |
nette/utils Version ^4.0 | — | — |
nette/application Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.