The MIT license, detailed README, tests, and release notes make adoption straightforward. Review the workflow’s broad token permissions and unpinned action, and note that the project has no published security policy.
88%
Total Score
100
100
93
67
Composer build tooling is present, but no security-scanning tool was detected; this is a modest supply-chain hygiene gap rather than evidence of abandonment.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, although active maintenance and organization backing partly offset the concern.
The single workflow has top-level write permissions and its one action reference is unpinned, both mild hygiene concerns. Its pull_request_target trigger has no untrusted checkout or script-injection sink, so these issues do not constitute a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
utopia-php/psr7 Version 0.2.* | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
utopia-php/client Version ^0.5 | — | — |
utopia-php/telemetry Version ^0.4.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.