There is no security policy, and both workflow actions are unpinned. The package is licensed, tested, non-deprecated, and backed by an organization-owned repository, but recent maintenance activity is limited.
61%
Total Score
75
100
83
67
The package has existed since January 2020 with 32 releases, but only one release in the last 12 months; this suggests a slower maintenance cadence despite a recent release.
There were zero commits and zero active maintainers in the three months measured. A recent push and release provide some compensation, but the current maintenance signal remains weak.
The repository has 11 stars, zero forks, and two watchers. This is limited community adoption, though popularity is only supporting evidence and does not outweigh the maintenance signals.
Composer build tooling is present, but no security-scanning tool was detected, leaving a meaningful repository hygiene gap for a dependency project.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/utils Version ^4.0 | — | — |
nette/database Version ^3.0 || ^4.0 | — | — |
nette/bootstrap Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.