Package Health

afragen/git-updater

This is a mature, actively maintained release with a long history, frequent stable releases, current repository activity, substantial test and documentation coverage, clear licensing, and a repository that directly matches the package. The main reservations are that registry publishing is controlled by one maintainer, recent commits are concentrated in one primary contributor, the repository has no detected security scanning or security policy, and its workflows do not declare top-level token permissions. These are meaningful hygiene and continuity concerns, but they do not outweigh the strong evidence of ongoing maintenance and project maturity.

Latest 14.4.2PackagistPackagist

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one account, Andy Fragen, has registry publish access. This is a continuity concern for publishing, although registry access does not by itself measure the number of active code maintainers.

Project backingcaution

The repository owner is an individual user rather than an organization. This does not negate the project's strong activity, but it provides less organizational maintenance redundancy than organization-backed ownership.

Repo bus factorcaution

Recent activity involves four contributors, but the top contributor accounts for about 69% of commits. The active secondary contributor accounts for about 29%, which provides some compensation, but the project still has a concentrated recent commit base.

Repo toolingcaution

Composer build tooling is used, but no security scanning tools were detected. The absence of automated security scanning is a hygiene gap, though it is not evidence that the release is unsafe or unmaintained.

Security policycaution

No repository security policy was detected. That reduces transparency about vulnerability reporting and handling, creating a modest security-maintenance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andy Fragen

Direct Dependencies

DependencyLast ReleaseScore
afragen/singleton
Version ^1.0
—
—
freemius/wordpress-sdk
Version ^2.12
—
—
afragen/wp-readme-parser
Version ^1.0
—
—
afragen/wp-dismiss-notice
Version *
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform