Documentation, licensing, tests, and release notes provide a solid basis for adoption. Recent commit activity is absent despite a current release, and all three workflow actions are unpinned, so ongoing maintenance and build reproducibility deserve caution.
68%
Total Score
83
50
94
100
The package has 13 runtime dependencies, including several closely related TomatoPHP and Filament components; this is substantial integration surface for an ecommerce plugin but fits its stated functionality.
The repository recorded zero commits and zero active maintainers in the last three months. The same-day push and current release partly offset this, but the recent development record is still thin.
Composer build tooling is present, but no security scanning tools were detected. This is a modest repository hygiene gap rather than evidence of abandonment.
The sole workflow was fully analyzed with no untrusted checkouts, injection findings, or audit findings, and it avoids broad top-level write permissions. However, all three action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
milon/barcode Version ^12.0|^13.0 | — | — |
filament/filament Version ^5.0 | — | — |
tomatophp/filament-cms Version ^5.0 | — | — |
flowframe/laravel-trend Version ^0.4.0|^0.5.0 | — | — |
tomatophp/filament-types Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.