Package Health

utopia-php/image

This release appears healthy and suitable for dependency use: it has a five-year history, regular recent releases, an active non-archived organization-backed repository, four active contributors in the last three months, balanced commit concentration, tests, a clear MIT license, and no install-time lifecycle scripts. The main reservations are repository security hygiene: the only workflow uses pull_request_target with top-level write permissions, no security policy or security scanning is reported, and issue/PR activity was quiet during the last month. These concerns warrant review of the workflow before adoption but do not outweigh the strong maintenance and project-backing evidence.

Latest 0.8.12PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

The sole workflow uses pull_request_target, which requires careful review because it runs in a privileged event context; however, no untrusted checkout or script injection was detected, limiting the net concern.

Repo issue activitycaution

There is one open issue and one open pull request, but no issues or pull requests were created or closed in the last month; this is a mild maintenance-activity gap, partly offset by recent commits and releases.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are reported, leaving a security-process gap for a package that handles image data.

Security policycaution

No repository security policy is present, reducing transparency about vulnerability reporting and response procedures.

Token permissionscaution

The workflow has top-level write token permissions. This expands the impact of a workflow compromise, although no untrusted checkout or script injection was reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
25 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform