Package Health

daun/statamic-embed-fieldtype

This is a healthy, actively maintained release with a clear MIT license, stable 1.3.2 versioning, recent and regular releases, a matching source repository, documented functionality, and repository tests that compensate for tests not being included in the artifact. The repository was pushed very recently and is not archived, while the package has a modest dependency footprint and no install-time lifecycle scripts. The main concerns are that all recent commits come from one contributor, no security policy or automated security scanning is present, and repository popularity is very low; these are meaningful transparency and continuity weaknesses but do not outweigh the strong release and source evidence.

Latest 1.3.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a continuity concern for a user-owned project, although repository activity shows that the maintainer is currently active.

Project backingcaution

The repository is owned by a user account rather than an organization, so the single-maintainer and single-publisher concentration is not offset by visible organizational backing.

Repo bus factorcaution

All 4 commits in the last 3 months came from one contributor, creating a genuine single-maintainer continuity risk with no second active contributor shown.

Repo popularitycaution

The repository has 0 stars and 1 fork, indicating limited external adoption or review. Popularity is supporting evidence rather than a decisive health criterion, so this is only a minor concern.

Repo toolingcaution

Composer build tooling is used, but no security scanning tools are detected. The missing scanning reduces assurance but is not by itself evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Philipp Daun

Direct Dependencies

DependencyLast ReleaseScore
embed/embed
Version ^4.4
statamic/cms
Version ^6.0

Weekly Downloads

Info

Last Published
15 days ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform