The package is actively released and the repository is maintained under organizational ownership. Its license records disagree, and recent work comes from one contributor, so continuity and licensing should be checked before adoption.
72%
Total Score
88
100
88
83
The manifest declares LGPL-3.0-only, while the artifact license file is recognised as MIT and belongs under a vendored dependency path. That mismatch creates licensing ambiguity despite a license file being present.
All nine recent commits came from one contributor, leaving a thin operational backup. Organizational ownership provides some handoff capacity but does not remove the concentration risk.
Composer is used as a build tool, but no security-scanning tool was detected. This is a hygiene gap rather than evidence of abandonment, especially given the recent release activity.
The repository has no security policy, reducing clarity about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.2.6 | — | — |
dravencms/admin Version ^2.3 | — | — |
dravencms/locale Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.