The README clearly explains installation and use, and the package is small with a modest runtime dependency set. Its workflow leaves both action references unpinned and the repository has no security scanning, while recent activity is absent.
58%
Total Score
50
100
83
75
The package is backed by a personal repository owner rather than an organization, so the small maintainer footprint offers no organizational redundancy.
Only two releases arrived on the same day, with no newer release for about six months. That leaves maintenance continuity unproven for a relatively new package.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with only two same-day releases, this is a meaningful maintenance concern.
Composer is used for the build, but no security-scanning tools are configured. That is a hygiene weakness for a package handling file uploads, though it is not evidence of abandonment by itself.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both of its two action references are unpinned. The lack of a top-level permissions block is acceptable on its own, while unpinned actions leave avoidable supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/http Version ^3.2 | — | — |
latte/latte Version ^3.0 | — | — |
nette/application Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.