Package Health

utopia-php/di

This release appears generally safe to depend on from a maintenance and transparency perspective: it has frequent recent releases, an active and unarchived repository, current commit activity from two contributors, an organization backing it, a matching repository with tests, an MIT license, and no registry deprecation. The main concerns are that it remains on an unstable 0.x major version, has a concentrated contributor base, lacks a security policy and automated security scanning, and uses a pull_request_target workflow with write-level token permissions. These workflow and governance gaps warrant review before adoption in a highly sensitive build environment, but the observed release and repository activity indicate a maintained project rather than an abandoned package.

Latest 0.3.6PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

The repository has one pull_request_target workflow, which can be sensitive when handling untrusted pull requests, although no untrusted checkout or script injection was detected.

Repo bus factorcaution

Two contributors are active, but the leading contributor made 7 of 9 recent commits, creating some concentration risk; organization backing provides partial resilience.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool is reported, leaving a security-hygiene gap.

Security policycaution

No SECURITY.md or equivalent security policy was found, reducing transparency about vulnerability reporting and response.

Token permissionscaution

The sole workflow declares top-level write token permissions, granting broader automation authority than a read-only configuration and increasing CI supply-chain exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
29 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform