The package is licensed, documented, and has repository tests with recent release activity. Organization ownership and a matching repository help, but maintenance is concentrated in one contributor and security and workflow safeguards are limited.
68%
Total Score
83
93
67
One contributor made all seven commits in the last three months, leaving no demonstrated second active maintainer. Organization backing provides some continuity, but the current activity still has a narrow operational base.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of a severe problem.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities. This lowers project transparency.
Both workflows were analyzed cleanly and contain no reported audit findings; the pull_request_target trigger has no untrusted checkout or script-injection sink. All three action references are unpinned, leaving a reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
konekt/enum Version ^4.2 | — | — |
konekt/xtend Version ^2.0 | — | — |
nette/schema Version ^1.2.5 | — | — |
konekt/address Version ^3.9 | — | — |
konekt/concord Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.