It has MIT licensing, tests, a changelog, release notes, and a repository that clearly matches the package. Organization backing and a security policy improve transparency, while nine runtime dependencies add upgrade surface.
58%
Total Score
75
50
83
100
Nine runtime dependencies, including several TomatoPHP modules and payment-related libraries, create a meaningful upgrade and compatibility surface for consumers.
The package has only three releases, all within about eight days, and none in the past two years; this indicates a long maintenance gap, though the release history is not large enough alone to show abandonment.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the registry’s extended release gap and reducing confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the package is unfit to use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
nesbot/carbon Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
bavix/laravel-wallet Version ^10.0 | — | — |
tomatophp/tomato-admin Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.