The source is organized, documented, and backed by an organization, with repository tests and no install-time scripts. Dependencies are substantial and workflow actions are unpinned, while no security policy is published.
55%
Total Score
75
50
80
75
The latest registry release was published in November 2020, nearly six years before collection, and there were no releases in the last 12 months. The 31-release history shows earlier activity but does not offset the current staleness.
The package declares nine runtime dependencies, including several framework components. This is a meaningful dependency surface but not, by itself, evidence of poor maintenance or unsafe adoption.
The repository recorded zero commits and zero active maintainers in the last three months, providing no recent maintenance evidence despite the repository being unarchived.
The linked repository has no published security policy, leaving vulnerability-reporting expectations and handling procedures unclear.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Both action references are unpinned, a supply-chain hygiene weakness, but not a severe risk alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^2.4.16 || ^3.0.5 | — | — |
nette/utils Version ^2.5.4 || ^3.1.3 | — | — |
nette/tester Version ^2.3.3 | — | — |
nette/security Version ^2.4.4 || ^3.0.5 | — | — |
nette/bootstrap Version ^2.4.6 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.