Package Health

goldnead/statamic-lead-magnets

This release appears healthy and reasonably safe to depend on from a maintenance and supply-chain transparency perspective. It is a young package, but it has released 10 times in 36 days, is on a stable major version, is not deprecated, has an active non-archived repository, and shows 49 commits from two active contributors in the last three months. The artifact is well-structured, includes a README, changelog, license file, and build workflows, while the absence of packaged tests is compensated by repository tests. The main concerns are the lack of a repository security policy, no configured security-scanning tool, and a workflow with top-level write permissions; these warrant review but do not indicate abandonment or make the package unfit to use.

Latest v3.6.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Project backingcaution

The repository is owned by the goldnead user account rather than an organization, so there is no organizational maintenance-backup signal. This is partly offset by two active contributors and the repository's recent commit volume.

Repo popularitycaution

The repository has zero stars, forks, and watchers, providing no popularity-based reassurance. Because the package is only 36 days old and popularity is supporting rather than decisive evidence, this is a minor caution rather than a health verdict.

Repo toolingcaution

The repository uses Composer build tooling, but no security-scanning tools are configured. The missing security automation is a genuine transparency and maintenance gap, although the package still has build infrastructure.

Security policycaution

The repository has no SECURITY.md or other declared security policy. This weakens vulnerability-reporting transparency and response expectations, especially for a package handling signed downloads and audit data.

Token permissionscaution

One workflow, release-dist.yml, has top-level write permissions, while the other is read-only. Broad write permission increases CI supply-chain exposure and should be narrowed to the minimum required permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adrian Goldner

Direct Dependencies

DependencyLast ReleaseScore
statamic/cms
Version ^6.0
laravel/framework
Version ^12.40|^13.0
goldnead/statamic-entitlements
Version ^1.0
pixelfear/composer-dist-plugin
Version ^0.1
goldnead/statamic-brand-context
Version ^1.13

Weekly Downloads

Info

Last Published
11 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform