Package Health

beromir/neos-studio-toggle-editor

This is a young but currently credible package: it has a clear GPL-3.0-or-later license, a stable v1.1.0 release, no registry deprecation, no install-time lifecycle scripts, and a linked repository that is active, unarchived, and has two recent contributors. The main reservations are limited maturity evidence from only two releases over 47 days, no tests or changelog in either the artifact or repository, minimal repository adoption, no security policy or automated security scanning, and a single registry maintainer. These concerns warrant review before adopting it for a critical dependency, but the recent activity and coherent package contents indicate it is presently usable rather than abandoned.

Latest v1.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which creates publishing continuity risk. The repository's two active contributors provide some maintenance compensation, but registry access itself remains concentrated.

Package scaffoldingcaution

A substantial README documents installation and configuration, but neither the artifact nor repository contains tests or a changelog. For a young UI package this is a genuine maintenance and transparency gap, though the README provides useful compensating documentation.

Project backingcaution

The repository is owned by an individual user rather than an organization, so maintenance continuity depends more directly on the small contributor group.

Release historycaution

The package is only 47 days old and has two releases, with a median interval of about 48 days. This is too short a history to demonstrate long-term maturity, although it does show an initial follow-up release rather than complete inactivity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool is reported. The missing scanning is a hygiene gap, although it is not by itself evidence of unsafe or abandoned maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Henrik Reißig

Direct Dependencies

DependencyLast ReleaseScore
neos/neos
Version ^9.1
medienreaktor/neos-studio
Version ^1.0

Weekly Downloads

Info

Last Published
16 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform