Package Health

afragen/github-updater

This is a mature, actively maintained release with a long history since 2014, 231 releases, 25 releases in the last 12 months, and a stable non-prerelease version. The linked repository is active, unarchived, well-popularized, has substantial recent commit and pull-request activity, tests, changelog, and reproducible-looking Composer-based project structure. The main concerns are that registry publishing is controlled by one maintainer, recent commits are concentrated in one primary contributor, the repository has no declared security policy or security scanning, workflow token permissions are not explicitly top-level constrained, and the repository does not match the package name or mention it in its README, creating some package-to-source transparency risk. Overall, it appears suitable to depend on, but the repository linkage and security-governance gaps warrant verification for security-sensitive deployments.

Latest 14.4.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account, Andy Fragen, has publish access. This is a modest publishing-resilience concern, though the repository's observed activity provides compensating evidence of ongoing maintenance.

Project backingcaution

The repository is owned by an individual GitHub user rather than an organization, so there is no organizational succession context to offset the single registry maintainer and concentrated commit activity.

Repo bus factorcaution

The primary contributor made about 69% of recent commits, creating concentration risk; however, a second contributor supplied about 29% and four contributors were active, so this is a caution rather than a severe abandonment signal.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Because this signal specifically indicates that the linked repository may not belong to the package, it is a meaningful source-to-package transparency concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The build setup is positive, while the missing security automation leaves a genuine governance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andy Fragen

Direct Dependencies

DependencyLast ReleaseScore
afragen/singleton
Version ^1.0
—
—
freemius/wordpress-sdk
Version ^2.12
—
—
afragen/wp-readme-parser
Version ^1.0
—
—
afragen/wp-dismiss-notice
Version *
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform