Clear licensing, documentation, tests, release notes, and a security policy make adoption easier. Organization backing and a matching repository help, but the project has little visible usage and no security scanning.
56%
Total Score
75
81
100
The package has had no release in more than two years, despite four releases concentrated in its first few weeks. This is a meaningful maintenance concern, though the repository remains active in ownership and is not archived.
There were zero commits and zero active maintainers in the past three months, consistent with the long release gap. This raises abandonment risk, but does not establish that the project is permanently abandoned.
The repository has zero stars, one fork, and one watcher, so there is little evidence of a broad user community or external review. Popularity is supporting evidence rather than a verdict, so this is a minor concern.
Composer build tooling is present, but no security scanning tools were detected. That limits automated assurance for a package with database, web, and application dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tomatophp/tomato-crm Version ^1.1 | — | — |
tomatophp/tomato-pms Version ^1.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
tomatophp/tomato-category Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.