Package Health

sashagm/notification

Tests, documentation, licensing, and a matching source repository provide a solid baseline. The project has had no registry release in two years and no recorded commits in the last three months, so maintenance should be watched closely.

Latest 1.14.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. That is not conclusive about project health, but combined with the lack of recent commits it leaves a thin apparent maintenance base.

Project backingcaution

The registry namespace and repository are owned by the same individual account, providing direct ownership alignment but no organizational backing to offset the thin maintainer base.

Release historycaution

The package has 20 releases, but none in the last 12 months; its latest release was in September 2024, indicating a prolonged release gap for a package with a two-year history.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of currently inactive development and raises abandonment risk.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and hygiene gap rather than evidence of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

sashagm

Direct Dependencies

DependencyLast ReleaseScore
twilio/sdk
Version ^7.5
—
—
irazasyed/telegram-bot-sdk
Version ^3.13
—
—
laravel-notification-channels/telegram
Version ^4.0 || ^5
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform