Package Health

bentools/webpush-bundle

Send push notifications through Web Push Protocol to your Symfony users.

Latest 0.14.1PackagistPackagist

68%

Total Score

caution

Usable with caveats: maintenance has gone quiet and workflow references are unpinned.

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed, which creates some publishing bus-factor concern. The long project history and recent releases partly compensate, and the repository owner is the same individual.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although a recent release shows some maintenance, the current lack of commit activity is a meaningful warning about responsiveness.

Repo toolingcaution

Composer is used for the build, but no security scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy. Consumers have no documented channel or process for reporting vulnerabilities, which lowers project transparency.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, both of its two action references are unpinned, leaving them exposed to upstream changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Beno!t POLASZEK

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^5.4 || ^6.0 || ^7.0 || ^8.0
—
—
guzzlehttp/guzzle
Version ^6.5.8 || ^7.4
—
—
minishlink/web-push
Version ^6.0.7 || ^7.0 || ^8.0 || ^9.0
—
—
symfony/http-kernel
Version ^5.4.20 || ^6.0 || ^7.0 || ^8.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform