The project has a small user footprint and limited security-process visibility. Its package structure, licensing, and recent release keep adoption reasonable, but workflow pinning needs attention.
68%
Total Score
75
100
89
75
The repository recorded zero commits and zero active maintainers in the last three months. A recent push and registry release partly offset this, but the observed development activity is still thin.
The repository has only 1 star, 1 fork, and 2 watchers. Low popularity is not decisive for a specialized library, but it provides little independent evidence of broad community support.
The repository uses Make and Composer, but no security scanning tools were detected, leaving security automation less visible.
No security policy was found in the repository, so the process for reporting and handling vulnerabilities is unclear.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both referenced actions are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.0 | — | — |
nette/utils Version ^3.0 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.