Clear licensing, documentation, security policy, and repository tooling support adoption. However, no commits were recorded in the last three months, while all 17 workflow actions are unpinned and a high-confidence bot-condition issue remains.
67%
Total Score
50
100
100
67
The package runs post-autoload-dump, post-install-cmd, and post-update-cmd scripts, which increases install-time behavior and deserves attention, but the signal alone does not show harmful or unusual actions.
The registry namespace and repository owner match, but ownership is an individual account rather than an organization, so the project has a relatively thin visible backing structure.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance concern that conflicts with the recent release and merged pull-request activity.
All seven workflows were analyzed, but all 17 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently dangerous.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guanguans/notify Version ^5.3 | — | — |
laravel/framework Version ^11.51 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.