Usable with caveats: the plugin is licensed, tested, documented, backed by an organization, and has a recent stable release, but maintenance has slowed. No releases occurred in the last 12 months and there were no commits in the last 3 months, so verify ongoing support before adopting it.
68%
Total Score
75
100
88
90
The package has existed since 2018 with 17 releases, but it has had no release in the last 12 months, which is a meaningful maintenance concern.
There were no commits or active maintainers in the last 3 months, indicating that maintenance has currently stalled and increasing abandonment risk.
There are no open issues and one open pull request, but no issues or pull requests were closed or merged in the last month; this supports the broader picture of limited recent activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The release workflow does not declare top-level token permissions, so its GitHub Actions permissions are less explicit than recommended.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yahnis-elsts/plugin-update-checker Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.