The package is licensed, documented, and backed by an organization with a security policy. Its release and commit activity stopped about two years and five months ago, so pinning v1.0.2 is prudent.
58%
Total Score
75
100
83
100
The package has only 3 releases, all concentrated around its initial publication, and none in the last 12 months; the latest release was about two years and five months ago. This is the clearest maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the latest push being about two years and five months ago. This materially raises abandonment risk.
The repository has 0 stars, 0 forks, and 1 watcher, indicating little visible adoption. Popularity is supporting evidence rather than a verdict, so this modestly limits confidence in project maturity.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap, partially offset by the repository's published security policy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tomatophp/tomato-admin Version ^1.2 | — | — |
nwidart/laravel-modules Version ^10.0 | — | — |
tomatophp/tomato-plugins Version ^1.2 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
joshbrw/laravel-module-installer Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.