Usable with caveats: the package is licensed, tested, documented, and backed by an active organization-owned repository. No registry release appeared in the last 12 months, and recent repository activity is quiet, so verify that maintenance still meets your needs before adopting it.
69%
Total Score
67
100
88
90
The package has existed since April 2018 with 26 releases and a roughly 50-day median interval, but it has had no registry release in the last 12 months; this indicates a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of currently quiet development and increases abandonment risk despite the recent push timestamp.
There are no open issues and two open pull requests, but no issues or pull requests were created or merged in the last month; this provides little evidence of current issue-handling activity.
Composer is used for builds, but no repository security scanning tool was detected; the missing scanning is a maintenance and transparency gap, though it is not by itself evidence of unsafe code.
The release workflow has no top-level token permissions declaration. No write permissions were observed, but the absence of an explicit restriction leaves avoidable CI permission ambiguity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yahnis-elsts/plugin-update-checker Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.