Package Health

forgelab-me/ci4-updater

The package has clear documentation, tests in the repository, a license, and no install-time scripts. Maintenance is concentrated in one contributor, and both analyzed workflow actions are unpinned, so keep those risks in mind.

Latest v2.17.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

One contributor made all 27 commits in the last 3 months, giving the project a very low bus factor. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. For a package that downloads and applies updates, this is a meaningful hygiene gap rather than evidence of unsafe behavior.

Workflow auditcaution

The sole workflow was fully analyzed, uses read-only permissions, and has no injection or high-severity findings. Both of its two action references are unpinned, leaving avoidable supply-chain drift risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ForgeLab

Direct Dependencies

DependencyLast ReleaseScore
codeigniter4/framework
Version ^4.4

Weekly Downloads

Info

Last Published
27 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform