Package Health

bpa/notifications-mattermost

The stable major version and small dependency set limit integration risk. However, the project has not been released or committed to since February 2019, and its tiny repository offers little documentation or testing support.

Latest v1.1PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

Only two releases were published, both in February 2019, with no releases in the last 12 months. This long release gap is strong evidence of abandonment risk.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the last repository push being in 2019. This is the clearest maintenance and abandonment concern.

Package file treecaution

The package and repository each contain only composer.json and two source files. This compact structure may fit a small notification handler, but it provides little visible project support beyond the implementation itself.

Package scaffoldingcaution

The artifact has no README, tests, or changelog, while the repository also has no tests or changelog. The GitHub release record is a small positive, but the missing consumer documentation and validation reduce transparency.

Project backingcaution

The package and repository are tied to the same individual owner rather than an organization. That is valid project backing, but it provides no visible organizational redundancy if the sole maintainer stops work.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benjamin Paap

Direct Dependencies

DependencyLast ReleaseScore
bpa/notifications
Version ~1.0
—
—
guzzlehttp/guzzle
Version ~6.0
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform