The package has clear documentation, tests, matching source, and an MIT license. Its short history, single recent commit, and one-contributor activity leave limited evidence of sustained maintenance.
64%
Total Score
50
92
83
The package is only 49 days old and has released once, so there is little evidence of a sustained release process. The otherwise complete package structure partly offsets the immaturity but does not establish long-term maintenance.
All recent commits come from one contributor, creating a narrow maintenance base. The repository owner is an individual rather than an organization, so there is no provided backing signal to offset that concentration.
Only one commit was recorded in the last three months, with one active maintainer. For a package this new that is not proof of abandonment, but it provides limited evidence of ongoing maintenance.
The repository has no security policy. This is a transparency gap for a package that exposes log browsing and access-control features, although it is not evidence of a security defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tobento/app Version ^2.0 | — | — |
tobento/app-card Version ^2.0 | — | — |
tobento/app-crud Version ^2.0 | — | — |
tobento/app-http Version ^2.0 | — | — |
tobento/app-user Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.