The README and focused dependency set make integration straightforward. No security policy and unpinned workflow actions leave maintenance and build hygiene weaker.
58%
Total Score
50
100
83
50
The repository is owned by an individual rather than an organization, so the limited maintainer and activity evidence is not offset by visible organizational backing.
The package has only two releases, both published on the same day, and no release activity since then despite being 188 days old. This provides limited evidence of sustained maintenance.
There were no commits and no active maintainers during the last three months. For a package released only 188 days ago, this is limited maintenance evidence and raises abandonment risk.
The repository has no stars, forks, or watchers. Popularity is only supporting evidence, but the absence of any adoption signal adds modest uncertainty for this new package.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene weakness rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.2 | — | — |
latte/latte Version ^3.0 | — | — |
nette/application Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.