The repository is correctly linked, not archived, and has no dangerous workflow findings. Its actions are unpinned and no security policy is published, leaving ongoing support and build hygiene uncertain.
52%
Total Score
50
71
75
Only two releases exist, with the latest in April 2016 and none in the past 12 months. This is a significant abandonment concern, though the repository was pushed later and is not archived.
There were no commits or active maintainers in the last three months. Combined with the old latest release, this weakens confidence in ongoing maintenance.
Composer is used for the build, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no published security policy, reducing clarity about vulnerability reporting and response expectations.
Version 0.9.1 is not marked prerelease, which helps consumers interpret this release, but the 0.x major version still signals an immature compatibility contract.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ~2.3@dev | — | — |
vimeo/vimeo-api Version ^1.2 | — | — |
nette/application Version ~2.3@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.