The package has a clear README, a matching source repository, and only one runtime dependency. However, its maintenance has been inactive for about six years, with no recent commits, tests, changelog, security policy, or scanning support.
42%
Total Score
50
100
71
50
The latest release was about six years ago, and there have been no releases in the last 12 months. Only three releases exist, indicating a largely inactive project.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long-term maintenance gap.
The published artifact includes a README, which supports basic use, and the absence of tests or a changelog in the artifact is normal packaging practice. The linked repository also reports no tests or changelog, which limits maintenance transparency.
Composer is used for the build, but the repository reports no security scanning tools. This is a hygiene gap rather than evidence that the package is unsafe.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.