Usable with caveats: it is a mature, licensed package with tests and a matching source repository, but maintenance appears to have stopped after the November 2022 release. Three years without releases or recent commits makes long-term support uncertain.
58%
Total Score
50
100
86
75
The repository recorded zero commits and zero active maintainers in the last three months. This is the strongest indication that active maintenance has collapsed.
The package has 41 releases over more than 13 years, but none in the last 12 months and its latest release was in November 2022. The long history supports maturity, while the prolonged release gap raises abandonment risk.
There were no new or closed issues and no merged pull requests in the last month, while 36 issues and 12 pull requests remain open. That backlog and inactivity add support to the maintenance concern.
Composer is used as the build tool, providing standard package build support, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence that the package is unsafe.
The repository has no security policy. That reduces transparency for vulnerability reporting, although it is less decisive than the demonstrated maintenance inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
nette/di Version ^3.0 | — | — |
nette/http Version ^3.0 | — | — |
nette/neon Version ^3.0 | — | — |
latte/latte Version ^2.5.2 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.