The package is clearly documented and its source matches the published artifact. Organization backing helps, but the project has no security policy and all recent work comes from one contributor.
64%
Total Score
83
86
50
The package is only 84 days old and all 10 releases arrived in a single day, showing active initial publication but little evidence of sustained release history.
One contributor made all 17 recent commits, leaving little demonstrated handoff capacity; organization ownership partly compensates but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, so users have no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
piko/i18n Version ^2.1 | — | — |
piko/user Version ^2.0 | — | — |
nette/utils Version ^4.1 | — | — |
piko/db-record Version ^2.0 | — | — |
piko/framework Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.