Usable with caveats: the release is stable, licensed, documented, tested, and recently published from an active repository. However, the project has no commits in the last three months, only one registry maintainer, and minimal adoption evidence.
72%
Total Score
67
100
89
88
Only one account has registry publish access, which creates a limited publishing base. The repository's matching project identity and recent release partly offset this, but do not remove the single-publisher dependency.
There were zero commits and zero active maintainers during the last three months. The recent release is reassuring, but the short-term absence of development activity is a meaningful maintenance concern.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little independent evidence of broad adoption.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and process gap, though it is not severe enough to make the release unfit on its own.
No repository security policy was found, reducing clarity about vulnerability reporting and response. This is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tobento/service-message Version ^2.0 | — | — |
tobento/service-support Version ^2.0 | — | — |
tobento/service-collection Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.