Package Health

utopia-php/compression

This is a generally healthy, actively maintained pre-1.0 package with clear MIT licensing, tests, a matching source repository, organizational backing, recent releases, and recent commits from two maintainers. Its main concerns are limited maturity and adoption signals, the absence of repository security scanning and a security policy, and a workflow using pull_request_target with top-level write permissions; these warrant review of the CI configuration but do not outweigh the evidence of active maintenance and package transparency.

Latest 0.1.8PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target, which can be security-sensitive even though no untrusted checkout or script injection was detected; this merits CI review.

Repo issue activitycaution

There is only 1 open issue and 1 open pull request, but no issues or pull requests were created or merged in the last month; this is a modest maintenance-activity gap rather than evidence of abandonment.

Repo popularitycaution

The repository has only 4 stars and 1 fork, indicating limited adoption, but popularity is supporting evidence and does not by itself undermine a maintained package.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap in repository automation.

Security policycaution

No security policy was found in the repository, reducing transparency around vulnerability reporting and coordinated disclosure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
29 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform