Package Health

tobento/service-notifier

The single-contributor project has limited handoff capacity, and the repository has no security policy or automated security scanning. Clear licensing, tests, documentation, and a stable release line reduce adoption risk.

Latest 2.0.5PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The repository owner is a user account rather than an organization, so there is no shown organizational handoff capacity to offset the concentrated contributor activity.

Repo bus factorcaution

One contributor made all 3 commits in the last 3 months, giving the project a fully concentrated recent commit share. That limits handoff capacity for a user-owned repository.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance-process gap, not evidence of unsafe code.

Security policycaution

The repository has no security policy. For a notification library, this weakens the documented path for reporting issues and handling security disclosures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tobias Strub

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—
psr/container
Version ^2.0
—
—
psr/http-message
Version ^2.0
—
—
symfony/notifier
Version ^7.3
—
—
psr/event-dispatcher
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform