Package Health

3xw/cakephp-attachment

New Attachment plugin for CakePHP

Latest 5.3.14PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Nine runtime dependencies, including CakePHP, Flysystem adapters, image processing, and JWT support, create meaningful transitive maintenance exposure but are coherent with the package's documented storage and media functionality.

Licensecaution

Neither a declared license nor a license file was detected. This is a genuine legal-transparency concern for adoption, although it does not by itself indicate technical abandonment.

Repo issue activitycaution

There are only 3 open issues and no recent issue or pull-request activity. This limits evidence of community engagement, but does not outweigh the recent release and commit activity.

Repo popularitycaution

The repository has only 3 stars, 0 forks, and 1 watcher, so external adoption and review are limited. This is supporting caution rather than a health verdict because the project shows strong release and commit activity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap, though it is not evidence that the package is unsafe or abandoned.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
cakephp/cakephp
Version ^5.0
—
—
firebase/php-jwt
Version ^7.0
—
—
3xw/cakephp-utils
Version ^5.0
—
—
friendsofcake/crud
Version ^7.0
—
—
intervention/image
Version ^2.3
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform