PHPackages                             montag-webstudios/composer-update-guard - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. montag-webstudios/composer-update-guard

ActiveComposer-plugin[Security](/categories/security)

montag-webstudios/composer-update-guard
=======================================

Composer plugin that requires confirmation before a full 'composer update'. Protects teams from accidental full dependency updates and supply-chain attacks. Targeted updates (composer update vendor/package) stay allowed.

v1.0.0(1w ago)02↓100%MITPHP &gt;=8.1

Since May 29Compare

[ Source](https://github.com/montag-webstudios/composer-update-guard)[ Packagist](https://packagist.org/packages/montag-webstudios/composer-update-guard)[ RSS](/packages/montag-webstudios-composer-update-guard/feed)WikiDiscussions Synced 1w ago

READMEChangelogDependencies (2)Versions (2)Used By (0)

### README not available

The README for this package hasn't been synced yet. View it on [GitHub](https://github.com/montag-webstudios/composer-update-guard).

###  Health Score

38

—

LowBetter than 83% of packages

Maintenance98

Actively maintained with recent releases

Popularity3

Limited adoption so far

Community2

Small or concentrated contributor base

Maturity42

Maturing project, gaining track record

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

12d ago

### Community

Maintainers

![](https://www.gravatar.com/avatar/154a5774d76d3e8a8e894ea067b80c226fa9adc1b225687611947e9c4827823c?d=identicon)[phschmanau](/maintainers/phschmanau)

---

Tags

plugincomposersecurityupdateguardsupply-chain

### Embed Badge

![Health badge](/badges/montag-webstudios-composer-update-guard/health.svg)

```
[![Health](https://phpackages.com/badges/montag-webstudios-composer-update-guard/health.svg)](https://phpackages.com/packages/montag-webstudios-composer-update-guard)
```

###  Alternatives

[pyrech/composer-changelogs

Display changelogs after each composer update

5974.2M28](/packages/pyrech-composer-changelogs)[sllh/composer-versions-check

Checks if packages are up to date to last major versions after update

2352.4M16](/packages/sllh-composer-versions-check)[dgtlss/warden

A Laravel package that proactively monitors your dependencies for security vulnerabilities by running automated composer audits and sending notifications via webhooks and email

8956.1k](/packages/dgtlss-warden)[bringyourownideas/silverstripe-maintenance

Toolset to help with the day by day maintenance work.

32223.7k5](/packages/bringyourownideas-silverstripe-maintenance)[bringyourownideas/silverstripe-composer-security-checker

Provides information if your SilverStripe application uses dependencies with known vulnerabilities.

10103.9k2](/packages/bringyourownideas-silverstripe-composer-security-checker)[padosoft/laravel-composer-security

Security checker for composer.lock.

324.1k](/packages/padosoft-laravel-composer-security)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
