Package Health

node-notifier

A Node.js module for sending notifications on native Mac, Windows (post and pre 8) and Linux (or Growl as fallback)

Latest 11.0.0NPMNPM

68%

Total Score

caution

A mature, licensed package is held back by no recent commits and weak workflow pinning.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity was provided, reducing publication transparency for this release.

Lifecycle scriptscaution

A prepare script runs during installation, which adds build-time behavior that consumers should understand, but this signal alone does not show harmful or unusual activity.

Maintainerscaution

The registry lists one publishing maintainer. The repository is user-owned rather than organization-backed, so there is little visible redundancy in publishing access.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign of slowed maintenance that is only partly offset by the recent release and issue activity.

Repo toolingcaution

The repository uses build and test tooling, but no security scanning tools were detected, leaving a modest assurance gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-7789
node-notifier is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 8.0.1.
0.0.0 - 8.0.1
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
growly
Version ^1.3.0
—
—
is-wsl
Version ^3.1.1
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
13 years ago
Unpacked Size
5.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform