There is no declared or detected license, and the package artifact has no README; the organization-owned repository provides some accountability. Its stable version and clean install metadata do not offset the maintenance uncertainty.
47%
Total Score
50
100
69
100
The package has 15 releases since September 2021, but the latest release was about 20 months ago and there were no releases in the last 12 months. This materially raises maintenance and abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, reinforcing the long release gap rather than showing ongoing maintenance.
Neither the registry metadata, package artifact, nor repository contains a recognized license. That creates a real transparency and adoption risk for downstream users.
The package has no README, while tests and a changelog are normally repository concerns and their absence is not itself a packaging gap. The exact version does have a GitHub release, which provides some release traceability.
The project uses Composer for its build or packaging process, but no security scanning tooling was detected. The missing scanning is a hygiene gap, not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/utils Version ^3.2 || ^4.0 | — | — |
nette/finder Version ^2.5 || ^3.0 | — | — |
nette/schema Version ^1.2 | — | — |
utilitte/php Version ^1.3 | — | — |
symfony/console Version ^5.3.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.