The repository has minimal adoption and no security policy or scanning, leaving little evidence of ongoing project care. Organization backing, a matching repository, and no install-time scripts provide limited reassurance.
32%
Total Score
50
67
75
The package has only one release, published in June 2014, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release silence and providing no evidence of current maintenance.
Three issues remain open, with no new or closed issues and no pull-request activity in the last month. This suggests unresolved maintenance needs, though the issue volume is small.
The repository has only 2 stars, 0 forks, and 2 watchers. Low popularity is supporting evidence rather than decisive on its own, but it offers little community resilience.
The project uses Composer, which supports reproducible package management, but has no detected security-scanning tooling. The missing scanning is a modest hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
latte/latte Version ~2.2 | — | — |
nette/nette Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.