The README, release notes, and MIT license provide useful documentation and clear usage rights. A small dependency set cannot offset the archived repository, absent recent commits, and package deprecation.
12%
Total Score
0
100
42
50
Packagist marks the entire package as abandoned and points to cslant/telegram-git-notifier-app as its replacement. This directly signals that developers should not start new dependencies on this package.
The latest release was in November 2023, with no releases in the last 12 months. The package had an active initial cadence but has since gone without a registry release for nearly three years.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the archived state and package deprecation, this indicates no current maintenance capacity.
The linked source repository is archived, which is a severe abandonment risk even though it was pushed recently. Archived projects generally should not be treated as an actively maintained dependency.
The linked repository name does not match the package name and its README does not mention this package. Although subpackages can use monorepositories, this mismatch leaves uncertainty about whether the source repository actually represents the published package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cslant/telegram-git-notifier Version ^1.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.