Package Health

onesignal/onesignal-php-api

This release appears healthy and suitable for dependency use: it is a stable, non-deprecated version with 23 releases over roughly 20 months, 18 releases in the last 12 months, and a median release interval of about 12 days. The repository is active, organization-backed, correctly associated with the package, not archived, and uses Composer plus CodeQL; recent activity includes 11 commits and 7 merged pull requests in the last 3 months. The main concerns are that the repository's recent commits are entirely attributed to a release bot, the artifact and repository report no tests, no security policy is present, and workflows lack top-level permission declarations. These are meaningful hygiene and resilience gaps, but they do not outweigh the strong release cadence, active repository state, and organization backing.

Latest 5.16.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The package includes a README and changelog, and the repository uses GitHub Releases, but neither the artifact nor repository reports tests. For an API client, the missing test evidence is a maintenance and regression-risk gap.

Repo bus factorcaution

All 11 recent commits came from one contributor, semantic-release-bot, giving the observed activity a weak human bus factor. Organization backing partly mitigates handoff risk, but the signal still warrants caution because no human contributor activity is shown.

Security policycaution

No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting and response expectations less transparent.

Token permissionscaution

All three workflows lack top-level permission declarations, although none declares top-level write permissions and two use job-level permissions. Explicit least-privilege declarations would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

OneSignal developers

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
guzzlehttp/guzzle
Version ^7.3

Weekly Downloads

Info

Last Published
14 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform