It has a clear license, a stable version, repository tests, and no install-time scripts. However, its maintenance signals are dated, and the repository has no security policy, leaving future compatibility and security response uncertain.
48%
Total Score
50
79
75
The latest release was about seven years ago, with no releases in the preceding 12 months. That strongly raises abandonment and compatibility risk, despite a history of 22 releases.
The repository recorded no commits and no active maintainers in the past three months, and its last push was about six years ago. This indicates very limited ongoing maintenance.
There were no new or closed issues in the past month and one open pull request. This is consistent with a largely inactive project, though the lack of open issues limits evidence of unresolved problems.
Composer build tooling is present, showing a defined package workflow, but no security-scanning tooling was detected. This is a modest hygiene gap rather than evidence that the release is unsafe.
The linked repository has no security policy. For a maintained dependency this weakens disclosure and response transparency, although the project’s broader inactivity is the more significant concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.0 | — | — |
nette/utils Version ^2.4 || ^3.0 | — | — |
doctrine/annotations Version ~1.6 | — | — |
kdyby/doctrine-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.