The package has a clear MIT license, useful documentation, tests, modest dependencies, and read-only workflow permissions. Its GitHub Actions references are unpinned, and the project lacks a security policy or scanning tools.
68%
Total Score
50
100
88
67
Only one registry account has publishing access. The matching user-owned repository makes this unsurprising, but it leaves limited publishing continuity if that maintainer becomes unavailable.
The package is only 80 days old with three releases, all published within about one day; this shows active initial publication but provides little long-term maintenance evidence.
One contributor made all three recent commits, leaving maintenance entirely concentrated in a single person.
There were three commits in the last three months, all within the short observed project history; this indicates some activity but not established ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving security-maintenance practices less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.