The repository remains active, tested, licensed, and backed by an organization, with a release published recently. Its workflows use seven unpinned actions and inherit secrets in one coverage workflow. Use contributte/api-router instead, as listed by the registry.
20%
Total Score
75
81
83
Packagist marks the entire package as abandoned and identifies contributte/api-router as its replacement. This is a severe adoption risk even though the repository remains active.
There were no commits and no active maintainers in the three months measured. That suggests limited recent development capacity, despite the recent release and repository push evidence.
The repository uses Composer and Make, but no security-scanning tools were detected. This is a hygiene gap rather than a standalone dependency risk.
All four workflows were analyzed with no untrusted checkouts or script injections, but all seven action references are unpinned and one high-confidence medium-severity finding reports inherited secrets in coverage.yml. These are workflow hygiene and exposure concerns, not a standalone reason for a critical score.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/di Version ^3.2.2 | — | — |
nette/http Version ^3.3.0 | — | — |
contributte/utils Version ^0.6.0 || ^0.7.0 | — | — |
nette/application Version ^3.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.