The package has a focused dependency set, a clear README, tests, and release notes. Its small project footprint offers little independent evidence beyond the maintainer's work.
68%
Total Score
50
94
50
Only one registry account has publish access. The repository is user-owned rather than organization-owned, so there is limited visible redundancy if that maintainer becomes unavailable.
There were no commits and no active maintainers in the three months measured, which weakens evidence of ongoing development; the recent release history partly offsets but does not remove that concern.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful security-process gap for a package that sends application notifications.
The repository has no published security policy, so users have no documented reporting process despite the README requesting private email reports.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hebinet/websms-client Version ^2.0 | — | — |
illuminate/notifications Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.