Package Health

tomatophp/tomato-category

manage category/tags/types for any model with splade/tomato PHP

Latest v1.1.10PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Dependency profilecaution

Four runtime dependencies form a moderate dependency surface for a PHP package, including the PHP runtime and three TomatoPHP components. This is not excessive, but it creates ongoing compatibility dependency on related packages.

Release historycaution

The package has 12 releases over roughly three years, but no releases in the last 12 months and the latest was in June 2024. This is a meaningful maintenance concern, though the prior regular cadence provides some maturity evidence.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Combined with no registry releases in the last 12 months, this indicates maintenance has gone quiet.

Repo toolingcaution

Composer is used for the build, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.

Workflow auditcaution

No GitHub Actions workflows were found, so there are no workflow findings or unpinned actions to weigh. This also means the repository provides no workflow-based automation or security checks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Fady Mondy

Direct Dependencies

DependencyLast ReleaseScore
tomatophp/tomato-admin
Version ^1.1
—
—
tomatophp/console-helpers
Version ^1.0
—
—
tomatophp/tomato-translations
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform