Package Health

utopia-php/dns

utopia-php/dns 3.0.7 appears healthy and reasonable to depend on: it is actively released, on a stable major version, backed by a non-archived organization-owned repository, and supported by six active contributors with balanced commit participation. The package is licensed, tested, clearly documented, and has no install-time lifecycle scripts. The main reservations are low repository popularity, no security policy or security-scanning tooling, and a mirror workflow using pull_request_target with write permissions; these are supply-chain hygiene concerns, but they do not outweigh the strong maintenance and project-backing evidence.

Latest 3.0.7PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

The single analyzed workflow uses pull_request_target, which can expose privileged workflow execution to pull-request event handling. No untrusted checkout or script injection was detected, so this is a contained but meaningful workflow-risk concern.

Repo issue activitycaution

There is one open issue and two open pull requests, with no issues or pull requests opened or merged in the last month. This suggests limited recent community workflow activity, although commit activity remains active.

Repo popularitycaution

The repository has only 8 stars, 0 forks, and 5 watchers. This is weak supporting evidence, though popularity alone is not decisive and the active contributor and release signals are stronger.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer is a genuine repository hygiene gap, not evidence that the package is malicious.

Security policycaution

No repository security policy was found, reducing transparency around vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eldad Fux

Direct Dependencies

DependencyLast ReleaseScore
utopia-php/domains
Version ^4.0.0
—
—
utopia-php/telemetry
Version ^0.4
—
—
utopia-php/validators
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform