Package Health

el-schneider/statamic-html-minify

This is a generally usable and transparently maintained package with a stable v2.1.0 release, a matching repository, documented configuration, a changelog, repository tests, Composer-based tooling, and Dependabot scanning. However, maintenance appears relatively lightweight: there have been only 8 releases over more than 6 years, just 1 release in the last 12 months, no commits or active maintainers in the last 3 months, and the repository has negligible adoption indicators. A single registry maintainer, absent security policy, write-enabled workflows, and a pull_request_target workflow add governance and operational concerns, though none independently make the package unfit to depend on.

Latest v2.1.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One of four workflows uses pull_request_target, specifically the Dependabot auto-merge workflow. No untrusted checkout or script-injection findings were detected, which limits but does not eliminate workflow-risk concerns.

Maintainerscaution

Only one account has registry publish access, creating a bus-factor concern for publishing continuity. The repository is user-owned rather than organization-owned, so there is no organizational backing signal to compensate for this.

Project backingcaution

The source repository is owned by the user account el-schneider, so the project has identifiable ownership but no demonstrated organization-level backing.

Release historycaution

The package has existed for about 6 years and has 8 releases, but only 1 release occurred in the last 12 months and the median release interval is about 154 days. This supports maturity but indicates a relatively slow release cadence.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers over the last 3 months. Although the latest release and repository push are recent, the recent commit silence raises maintenance-continuity risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vaggelis Yfantis

Direct Dependencies

DependencyLast ReleaseScore
statamic/cms
Version ^5.0 || ^6.0
—
—
voku/html-min
Version ^5.0
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform