Package Health

hintik/nette-base-project

The repository is actively maintained, with 68 commits in three months split evenly between two contributors, and the package includes tests and a substantial README. Missing security scanning and policy, plus all 22 workflow actions being unpinned, leave meaningful maintenance and build-reproducibility gaps.

Latest v1.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Dependency profilecaution

The package declares 21 runtime dependencies for a full Nette application skeleton, a substantial but contextually expected dependency surface for the functionality described.

Maintainerscaution

Only one registry account has publish access, which creates publishing continuity risk; the repository's two active contributors provide some compensation but do not eliminate it.

Project backingcaution

The repository is owned by an individual account rather than an organization, so the small maintainer base has less organizational redundancy.

Repo issue activitycaution

Two open issues and no recent issue or pull-request movement are a minor transparency gap, but this is outweighed by the recent commit activity.

Repo toolingcaution

Make and Composer build tooling are present, but no security-scanning tools were detected, leaving a modest assurance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jan Hinterholzinger

Direct Dependencies

DependencyLast ReleaseScore
nette/di
Version ^3.2
—
—
nette/http
Version ^3.3
—
—
nette/mail
Version ^4.0
—
—
latte/latte
Version ^3.1
—
—
nette/forms
Version ^3.2
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform