A single maintainer and no commits in three months leave limited evidence of ongoing maintenance. Tests, release notes, security tooling, and pinned workflow actions provide useful support, but the audit was incomplete.
68%
Total Score
50
100
50
An install-time post-root-package-install script runs during installation, adding some execution complexity and a modest supply-chain review concern.
Only one registry publishing maintainer is listed, leaving a thin publishing base and increasing continuity risk if that maintainer becomes unavailable.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance warning that is partly offset by the recent push and registry releases.
There is one open issue and two open pull requests, with one new pull request in the last month; this shows some current engagement, although no pull requests were merged in that period.
The repository has no security policy, leaving vulnerability reporting and maintainer response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/neon Version ^3.3 | — | — |
nette/finder Version ^3.0 | — | — |
symfony/yaml Version ^6.2 || ^7.0 | — | — |
symfony/console Version ^6.2 || ^7.0 | — | — |
opis/json-schema Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.