Package Health

rollswan/laravel-project-updater

The codebase is small and easy to inspect, with a clear README and only two runtime dependencies. Its lack of tests, security scanning, and an install-time script adds maintenance and review risk.

Latest 1.0.17PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has only two releases, both within six days in June 2021, followed by more than five years without a release. This is strong evidence of abandonment risk despite the repository not being archived.

Lifecycle scriptscaution

A post-install command runs during installation, adding execution and review surface beyond ordinary file installation. No provided signal shows that this script is unsafe or necessary, so it remains a caution rather than a severe finding.

Maintainerscaution

The registry lists one maintainer, which is normal for an individually owned package but leaves limited visible publishing redundancy when combined with the stale release history.

Repo issue activitycaution

There are no open issues or pull requests and no recent activity. While a quiet issue tracker can be healthy for a stable project, here it offers no counterweight to the long maintenance gap.

Repo popularitycaution

The repository has one star and no forks, providing little adoption evidence. Popularity is only supporting evidence, so this does not independently make the package unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rollswan Acebedo

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version ~7
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform