Package Health

goldnead/statamic-notifications

This release appears healthy and suitable to depend on, with strong evidence of active development, coherent package/repository ownership, mature repository hygiene, and no deprecation or workflow-risk indicators. The package is still young at 43 days old, and its zero popularity and single registry maintainer provide limited external validation, but these concerns are substantially offset by 18 releases, 76 recent commits from three contributors, repository tests and changelog coverage, a security policy, and read-only CI token permissions. Confidence is high, though some signal categories were not collected.

Latest v1.9.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access, which limits registry-side redundancy. This is a caution rather than a severe concern because repository activity shows three active contributors and the signal measures access, not actual maintenance.

Project backingcaution

The repository is owned by the user account goldnead rather than an organization. This does not provide organizational succession support, but it is consistent with the directly matching repository and should be weighed alongside the three active contributors.

Release historycaution

The package is young at 43 days but has 18 releases, all within the last 12 months, with a median interval of about 1.1 days. This demonstrates active delivery, although the short history limits evidence of long-term stability.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is little external adoption evidence. Popularity is supporting evidence only, and the package's active release and commit signals offset this weakness.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, partially offset by the repository's security policy and conservative workflow permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adrian Goldner

Direct Dependencies

DependencyLast ReleaseScore
statamic/cms
Version ^6.0
laravel/framework
Version ^12.0|^13.0
goldnead/statamic-suppression
Version ^1.0
goldnead/statamic-brand-context
Version ^1.13
goldnead/statamic-identity-contracts
Version ^1.0

Weekly Downloads

Info

Last Published
13 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform