The package has a clear MIT license, repository tests, documentation, and no install-time scripts. Its short release history and weak repository security hygiene leave some uncertainty about continued support.
61%
Total Score
50
100
88
75
Only two releases have been published, about 31 days apart, so the project has limited evidence of an established maintenance track record.
No commits and no active maintainers were recorded in the last three months, which is a meaningful sign of slowed maintenance for a recently released package.
Composer build tooling is present, but no security-scanning tool was detected, leaving a repository hygiene gap.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
The sole workflow was fully analyzed with no high-confidence audit findings, but all 7 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
skie/notification Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.