Package Health

goldnead/statamic-toc

This release appears healthy and suitable to depend on: it has been maintained since 2021, has 7 releases in the last 12 months, is on a stable major version, is not deprecated, and the linked repository is active and unarchived with 52 commits from two active contributors in the last three months. The package includes a substantial README, changelog, license file, focused runtime dependency set, and no install-time lifecycle scripts; repository tests compensate for tests not being included in the artifact. The main reservations are low repository popularity, no declared security policy or security-scanning tooling, and limited recent issue activity, but these do not outweigh the strong release and maintenance evidence.

Latest v2.3.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The repository is owned by an individual rather than an organization, so formal organizational maintenance handoff cannot be assumed. Nevertheless, two contributors are demonstrably active in the recent commit history.

Repo popularitycaution

The repository has only 2 stars, 8 forks, and 1 watcher, indicating limited adoption or community visibility. Popularity is supporting evidence rather than a decisive health criterion, so this is a modest concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap, though it is not evidence of abandonment and is partly mitigated by the repository's other CI and workflow controls.

Security policycaution

The repository has no SECURITY.md or other detected security policy, which reduces vulnerability-reporting transparency for dependents.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adrian Goldner

Direct Dependencies

DependencyLast ReleaseScore
statamic/cms
Version ^5.0 | ^6.0
league/commonmark
Version ^2.0

Weekly Downloads

Info

Last Published
13 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform