The organization-backed project is actively released and has a clear README. Its single active contributor, missing license file, install hooks, and unpinned workflow actions leave meaningful maintenance and publishing gaps.
68%
Total Score
83
94
50
No license declaration or license file was detected in the package or repository, so the terms for using this project are unclear despite the README displaying an MIT badge.
Install and update lifecycle scripts run automatically, adding publishing and installation complexity that consumers should account for.
All 8 recent commits came from one active contributor, leaving maintenance dependent on a single person even though the repository is organization-owned.
The repository has no published security policy, reducing transparency about vulnerability reporting and response.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
latte/latte Version ^3.1 | — | — |
tracy/tracy Version ^2.11 | — | — |
nette/assets Version ^1.0 | — | — |
drago-ex/bootstrap Version ^2.0 | — | — |
nette/robot-loader Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.