Package Health

guanguans/laravel-exception-notify

Clear licensing, documentation, security policy, and repository tooling support adoption. However, no commits were recorded in the last three months, while all 17 workflow actions are unpinned and a high-confidence bot-condition issue remains.

Latest 7.0.3PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-autoload-dump, post-install-cmd, and post-update-cmd scripts, which increases install-time behavior and deserves attention, but the signal alone does not show harmful or unusual actions.

Project backingcaution

The registry namespace and repository owner match, but ownership is an individual account rather than an organization, so the project has a relatively thin visible backing structure.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance concern that conflicts with the recent release and merged pull-request activity.

Workflow auditcaution

All seven workflows were analyzed, but all 17 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently dangerous.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

guanguans

Direct Dependencies

DependencyLast ReleaseScore
guanguans/notify
Version ^5.3
—
—
laravel/framework
Version ^11.51 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform