Package Health

jooservices/laravel-notifications

The repository has clear documentation, tests, release notes, and broad automated security tooling. Organization backing and active pull requests help, but this is too new to demonstrate sustained maintenance, and workflow references need tighter pinning.

Latest v1.0.1PackagistPackagist

63%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These add installation-time execution surface, though the signal does not show that the scripts are harmful or unusually broad.

Release historycaution

The package is only 0 days old with two releases published within roughly one hour, so there is not yet enough history to establish dependable maintenance or release continuity.

Repo commit activitycaution

No commits or active maintainers were recorded in the last three months. Because the project is newly published, this is primarily a lack of established maintenance evidence rather than proof of abandonment.

Workflow auditcaution

All 11 workflows were analyzed with no reported audit findings or untrusted checkout/script-injection sinks. However, 40 of 47 action references are unpinned, and four workflows grant top-level write permissions, creating avoidable workflow-supply-chain and token-scope exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Viet Vu

Direct Dependencies

DependencyLast ReleaseScore
illuminate/mail
Version ^12.0|^13.0
jooservices/dto
Version ^3.2
illuminate/support
Version ^12.0|^13.0
jooservices/client
Version ^4.0
illuminate/contracts
Version ^12.0|^13.0

Weekly Downloads

Info

Last Published
3 hours ago
Created
4 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform