Package Health

pheature/toggle-crud

Usable with caveats: the package is licensed, tested, documented, and backed by a matching organization repository, but it has had no registry release for over two years and no commits in the last three months. Install-time scripts are absent and the repository uses security tooling, reducing operational risk despite the aging maintenance record.

Latest 0.8.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has 10 releases over roughly five years with a median interval of about 43 days, but the latest release was over two years ago and there were no releases in the last 12 months. This materially lowers confidence in continued maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed in November 2024, the current lack of recent development indicates slowed maintenance.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting guidance unclear. The presence of Dependabot and Psalm provides some compensation, but not a complete replacement for a documented reporting process.

Token permissionscaution

All four workflows lack top-level token permission declarations, so their permissions are not explicitly minimized at workflow scope. No workflow requests top-level write access, which limits the severity of this hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

kpicaza
pcs289
xserrat

Direct Dependencies

DependencyLast ReleaseScore
pheature/toggle-core
Version ^0.8
—
—
psr/event-dispatcher
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform