Its small, focused artifact has a clear README and license, but offers no security policy or automated security scanning. Pin v1.1.3 only after confirming its framework dependencies work in your application.
43%
Total Score
50
50
83
75
The release declares eight runtime dependencies, including framework and database integrations, creating a meaningful compatibility surface for a package with no recent maintenance evidence.
The repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible backing for a project already showing no recent activity.
The package has made no release in nearly seven years, despite five releases overall; this is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long-term maintenance concern.
There are no open issues or pull requests and no activity in the last month; this is consistent with an inactive project, though it does not show unresolved backlog.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^2.4 | — | — |
nette/forms Version ^2.4 | — | — |
nette/utils Version ^2.5 | — | — |
tracy/tracy Version ^2.6 | — | — |
kdyby/doctrine Version ~3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.