Package Health

guanguans/notify

Push notification SDK(AnPush、Bark、Chanify、DingTalk、Discord、Gitter、GoogleChat、IGot、Lark、Mattermost、MicrosoftTeams、NotifyX、NowPush、Ntfy、Push、Pushback、PushBullet、PushDeer、PushMe、Pushover、PushPlus、QQ、RocketChat、ServerChan、ShowdocPush、SimplePush、Slack、Telegram、WeWork、WPush、XiZhi、YiFengChuanHua、ZohoCliq、ZohoCliqWebHook、Zulip).

Latest 5.3.0PackagistPackagist

70%

Total Score

caution

Usable with caveats: active releases are offset by a single active contributor and weak workflow pinning.

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These scripts increase installation complexity and warrant some caution, although no separate evidence here shows that they are unsafe.

Project backingcaution

The repository is owned by an individual user rather than an organization. That does not indicate abandonment, but it provides no organizational handoff cushion for the single-contributor activity shown elsewhere.

Repo bus factorcaution

All three recent commits came from one contributor, giving that contributor a 100% share of recent activity. The package therefore has limited maintenance redundancy.

Repo commit activitycaution

The repository had three commits in the last three months, showing recent work, but the volume is modest for a package with this many integrations.

Workflow auditcaution

All seven workflows were analyzed, but all 17 action references are unpinned, two workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the pull_request_target workflow. The audit also found a low-confidence-impact adhoc package installation, creating notable workflow hygiene risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

guanguans

Direct Dependencies

DependencyLast ReleaseScore
psr/simple-cache
Version ^1.0 || ^2.0 || ^3.0
—
—
guzzlehttp/guzzle
Version ^7.15 || ^8.0
—
—
guzzlehttp/uri-template
Version ^1.0 || ^2.0
—
—
symfony/options-resolver
Version ^7.4 || ^8.0
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform