The package is licensed, documented, tested, and has recent release notes. Its workflow has no audit findings, though all six action references are unpinned and no security policy is published.
68%
Total Score
63
100
75
Only one registry account has publishing access. This is a modest operational concentration concern, reinforced by the repository activity showing one active contributor.
The repository is owned by a user rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational backing.
One contributor made all 17 commits in the last 3 months, leaving no demonstrated handoff capacity if that maintainer becomes unavailable.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The single workflow was fully analyzed with no findings, no untrusted checkouts, and no script injection. However, all 6 action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.0 | — | — |
almasaeed2010/adminlte Version ^4.4 | — | — |
friendsofcake/bootstrap-ui Version ^5.0 | — | — |
arodu/cakephp-bootstrap-tools Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.