New Attachment plugin for CakePHP
82%
Total Score
88
50
83
90
Nine runtime dependencies, including CakePHP, Flysystem adapters, image processing, and JWT support, create meaningful transitive maintenance exposure but are coherent with the package's documented storage and media functionality.
Neither a declared license nor a license file was detected. This is a genuine legal-transparency concern for adoption, although it does not by itself indicate technical abandonment.
There are only 3 open issues and no recent issue or pull-request activity. This limits evidence of community engagement, but does not outweigh the recent release and commit activity.
The repository has only 3 stars, 0 forks, and 1 watcher, so external adoption and review are limited. This is supporting caution rather than a health verdict because the project shows strong release and commit activity.
Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap, though it is not evidence that the package is unsafe or abandoned.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
3xw/cakephp-utils Version ^5.0 | — | — |
friendsofcake/crud Version ^7.0 | — | — |
intervention/image Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.