Its MIT license and focused seven-file artifact reduce transparency concerns. The lack of a security policy and security scanning leaves little evidence of ongoing stewardship.
42%
Total Score
71
75
The latest release was in December 2017, with no releases in the last 12 months after 16 total releases. This long publishing gap is a substantial abandonment concern.
The repository name matches the package, reducing the risk of a mismatched source repository, but the README does not mention the package explicitly. This is a minor transparency gap.
Composer is used for builds, but no security scanning tools are configured. For a small package this is not decisive alone, but it provides little supply-chain assurance alongside the stale project activity.
The repository is not archived, which preserves a basic maintenance path, but it was last pushed in October 2018. The prolonged absence of source updates lowers confidence in continued support.
No security policy is present in the linked repository, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ~2.4 | — | — |
nattreid/utils Version ~1.0 | — | — |
nette/reflection Version ~2.4 | — | — |
nette/application Version ~2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.