The MIT license and detailed README make the package easier to evaluate and adopt. Its single-maintainer setup, absent security policy, and unusual self-dependency leave limited evidence of ongoing care.
42%
Total Score
33
50
81
75
Only two releases were published, with the latest in November 2017 and none in the last 12 months; the package is about 9 years old with no newer registry maintenance evidence.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has not shown recent development activity.
Three runtime dependencies are declared, including the package itself; that self-dependency is unusual and warrants checking because it can complicate resolution and release maintenance.
Only one registry publishing account is listed, indicating a thin release surface; the linked repository is also owned by an individual rather than an organization, so no organizational backing compensates for it.
One issue and one pull request remain open, with no new or closed items in the last month, providing no evidence of current issue resolution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
boneq/laravel-onenet Version 1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.