Package Health

coldtrick/oembed

This is a mature, stable, non-deprecated package with a linked, organization-owned repository, a matching project README, recent publication activity, a small runtime dependency footprint, and documented CI workflows. The main concerns are that repository commit activity shows no active maintainers in the last 3 months, the package and repository contain no tests despite a PHPUnit workflow, security scanning and a security policy are absent, and workflow token permissions are not explicitly constrained; these are meaningful hygiene and maintenance risks, but they are partially offset by the very recent release and repository push, long release history, clean workflow-risk analysis, and clear package structure.

Latest v5.2.2PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The artifact has a substantive README and changelog, but neither the artifact nor repository has tests; the README documents features and developer extension points, while the missing tests reduce verification transparency.

Repo commit activitycaution

The repository records 0 commits and 0 active maintainers in the last 3 months, a direct maintenance warning. The very recent repository push and four releases in the last year partly compensate, so this is caution rather than danger.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently unhealthy for a small stable plugin, but it provides little evidence of active community maintenance.

Repo popularitycaution

The repository has only 3 stars and 2 forks, indicating a small user and contributor footprint. Popularity is supporting evidence rather than a verdict, so this warrants only a mild concern.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured. The missing scanning lowers supply-chain hygiene, while the existence of build tooling provides basic project structure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
embed/embed
Version ~4.4.0
—
—

Weekly Downloads

Info

Last Published
25 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform