The repository has tests, release notes, and a clear license, while Dependabot provides some maintenance support. Missing security-policy documentation and fully unpinned workflow references leave avoidable transparency and build-reproducibility gaps.
67%
Total Score
83
50
94
50
Six runtime dependencies, including CakePHP and Elasticsearch components, create a meaningful dependency surface for consumers, though the profile is not unusually large for this plugin.
The package has existed for about 3 years and the latest release was published recently, but only one release appeared in the last 12 months, indicating a slow release cadence.
No commits and no active maintainers were recorded in the last three months. The recent release and merged pull request provide some counterevidence, but the current maintenance signal is weak.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a package that integrates with external search services.
Both workflows were analyzed successfully and the pull_request_target trigger has no untrusted checkout or script-injection sink. However, all eight action references are unpinned, and the auditor reported low-confidence unpinned container-image findings, creating build-reproducibility and workflow-hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bedita/core Version ^6.0.0 | — | — |
cakephp/cakephp Version ^5.2.0 | — | — |
ruflin/elastica Version ^9.0 | — | — |
cakephp/elastic-search Version ^5.0 | — | — |
elasticsearch/elasticsearch Version ^9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.