A Node.js module for sending notifications on native Mac, Windows (post and pre 8) and Linux (or Growl as fallback)
68%
Total Score
caution
A mature, licensed package is held back by no recent commits and weak workflow pinning.
No build attestation or trusted-publisher identity was provided, reducing publication transparency for this release.
A prepare script runs during installation, which adds build-time behavior that consumers should understand, but this signal alone does not show harmful or unusual activity.
The registry lists one publishing maintainer. The repository is user-owned rather than organization-backed, so there is little visible redundancy in publishing access.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign of slowed maintenance that is only partly offset by the recent release and issue activity.
The repository uses build and test tooling, but no security scanning tools were detected, leaving a modest assurance gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-7789 node-notifier is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 8.0.1. | 0.0.0 - 8.0.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
growly Version ^1.3.0 | — | — |
is-wsl Version ^3.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.