Package Health

hpbxxtr/composer-upgrade-interactive

Tests, release notes, and security scanning provide solid project discipline. All recent commits come from one contributor, and the workflows leave all 15 actions unpinned, including a high-confidence unpinned container image finding. Depend on it with workflow and maintenance risk in mind.

Latest v0.4.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Project backingcaution

The registry and repository are owned by the same individual account, so the single-maintainer concentration is not offset by organizational backing.

Repo bus factorcaution

One contributor made all six commits in the last three months, leaving no demonstrated handoff capacity and increasing abandonment risk if that maintainer becomes unavailable.

Security policycaution

The repository has no security policy, a transparency gap for a package that performs dependency upgrades, though automated security scanning partly compensates.

Version stabilitycaution

Version 0.4.1 is not a stable-major release, but it is a normal release rather than a prerelease and recent releases contain no prereleases.

Workflow auditcaution

All 15 action references are unpinned, and a high-confidence audit found an unpinned container image; the separate low-confidence cache-poisoning finding is only a hygiene concern. Three workflows also grant top-level write permissions, without untrusted checkout or script-injection paths.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hagen Pommer

Direct Dependencies

DependencyLast ReleaseScore
laravel/prompts
Version 0.3.24

Weekly Downloads

Info

Last Published
14 hours ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform