The package has a clear README, a declared LGPL license, and a small dependency surface. Its tiny user base, single maintainer, and lack of security tooling reduce confidence, although it is neither deprecated nor archived.
73%
Total Score
67
100
88
83
Only one registry account has publishing access, which limits publishing redundancy, though the linked project is owned by the same individual.
The package has existed for over 11 years and published one release in the last 12 months, but only five releases overall with a median gap of about 2 years and 9 months indicate a sparse cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months. The recent release provides some compensating evidence, but current maintenance activity is still limited.
Composer is used for the build, but no security scanning tools are configured, leaving a modest repository-hygiene gap.
The repository has no security policy. For a small library this is a transparency gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/utils Version ^4.0 | — | — |
nette/application Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.