Package Health

avto-dev/firebase-notifications-laravel

Healthy and reasonable to depend on. It has a current stable release, a matching organization-backed repository with recent commits, tests, release notes, and a clear license; the main caveats are modest release frequency and limited security-policy and workflow-permission hardening.

Latest v2.10.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo popularitycaution

The repository has only 1 star and 7 forks, indicating limited adoption evidence. Popularity is supporting evidence rather than a decisive health measure, and the recent release and project practices compensate for the small audience.

Repo toolingcaution

The project uses Make and Composer, but no security-scanning tools were detected. This is a transparency and hardening gap, though it is not severe given the other repository evidence.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance unclear. This lowers transparency but does not by itself indicate that the package is unsafe to depend on.

Token permissionscaution

The single workflow has no top-level GitHub Actions token permissions declaration. No write permissions or dangerous workflow patterns were detected, but explicitly restricting permissions would provide stronger build-security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

avto-dev

Direct Dependencies

DependencyLast ReleaseScore
google/apiclient
Version ^2.2
guzzlehttp/guzzle
Version ~7.5
illuminate/config
Version ~11.0 || ~12.0 || ~13.0
illuminate/support
Version ~11.0 || ~12.0 || ~13.0
illuminate/contracts
Version ~11.0 || ~12.0 || ~13.0

Weekly Downloads

Info

Last Published
1 month ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform