The package has a clear README, a substantial source tree, and no install-time scripts. Its maintenance is quiet, licensing is inconsistent, and the linked repository does not identify the package.
48%
Total Score
50
100
64
100
The manifest declares a proprietary license, while the README says MIT and no license file was detected in the package or repository. This unresolved mismatch materially weakens licensing transparency.
Only 6 releases have been published since July 2021, with no releases in the last 12 months and a median interval of about 426 days. This indicates a slow maintenance cadence for a generator dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the latest push aligns with the latest release, current maintenance capacity is not demonstrated.
The linked repository name does not match the package name and its README does not mention the package. That makes package ownership and source correspondence harder to verify.
Composer and Make are used for project tooling, but no security scanning tool is present. This is a modest transparency and hygiene gap rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/utils Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.