Its documentation, licensing, and release notes support straightforward adoption. Recent activity is concentrated in one contributor, and every workflow action is unpinned, leaving meaningful maintenance and build-integrity concerns.
82%
Total Score
83
94
100
Only one contributor made all 11 commits in the last three months. Organization backing helps with handoff potential, but no second recently active contributor is shown, so maintenance continuity remains a caution.
Composer is used for builds, but no security-scanning tool was detected. The missing scanner is a hygiene limitation, not evidence that the package is unsafe or abandoned.
All three workflows were analyzed successfully with no audit findings, no untrusted checkouts, and no script injection; their lack of top-level permissions is acceptable. However, all 13 analyzed action references are unpinned, weakening build reproducibility and supply-chain integrity.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-15227 nette/application is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 2.2.0 - 2.2.10, 2.3.0 - 2.3.14, 2.4.0 - 2.4.16, 3.0.0 - 3.0.6, 2.0.0 - 2.0.19 and 2.1.0 - 2.1.13. | 2.0.0 - 2.0.192.1.0 - 2.1.132.2.0 - 2.2.10 +3 more | High |
| Dependency | Last Release | Score |
|---|---|---|
nette/http Version ^3.4 | — | — |
nette/utils Version ^4.1 | — | — |
nette/routing Version ^3.1.1 | — | — |
nette/component-model Version ^3.2 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.