The stable major version and small dependency set limit integration risk. However, the project has not been released or committed to since February 2019, and its tiny repository offers little documentation or testing support.
40%
Total Score
33
100
56
67
Only two releases were published, both in February 2019, with no releases in the last 12 months. This long release gap is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the last repository push being in 2019. This is the clearest maintenance and abandonment concern.
The package and repository each contain only composer.json and two source files. This compact structure may fit a small notification handler, but it provides little visible project support beyond the implementation itself.
The artifact has no README, tests, or changelog, while the repository also has no tests or changelog. The GitHub release record is a small positive, but the missing consumer documentation and validation reduce transparency.
The package and repository are tied to the same individual owner rather than an organization. That is valid project backing, but it provides no visible organizational redundancy if the sole maintainer stops work.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bpa/notifications Version ~1.0 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.