Package Health

spicyweb/craft-embedded-assets

This is a mature, actively published package with more than ten years of release history, 118 releases, a current stable version, a non-archived repository, and organization backing from Spicy Web. Its main concerns are limited recent development activity—only 2 commits in the last 3 months from one contributor—and the absence of repository security scanning, a security policy, and tests. Those gaps warrant monitoring and review before adoption, but the strong release cadence, documentation, changelog, licensing, and maintained repository make it a generally reasonable dependency.

Latest 5.4.9PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact has a README and changelog, and the repository also has a changelog and uses GitHub Releases. Tests are absent in both places, which is a modest transparency gap for a plugin with substantial source code.

Repo bus factorcaution

All 2 recent commits came from one contributor, giving a 100% top-contributor share. This is a genuine continuity concern, although organization ownership provides some potential for handoff.

Repo commit activitycaution

There were 2 commits in the last 3 months with 1 active maintainer. Recent work has not stopped, but the low volume suggests maintenance capacity may be constrained.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured. The build tooling is positive, while the missing scanning reduces supply-chain transparency.

Security policycaution

No repository security policy was found. This weakens vulnerability-reporting transparency, though it is a hygiene gap rather than evidence that the package is unmaintained.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Spicy Web

Direct Dependencies

DependencyLast ReleaseScore
embed/embed
Version ^4.4.10
craftcms/cms
Version ^5.0.0

Weekly Downloads

Info

Last Published
18 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform