Usable, but you’re depending on an effectively abandoned plugin: the only release was in 2017 and the repo shows no recent commits or issue activity. It has a declared MIT license and includes a README plus basic tests, but there’s no ongoing maintenance signal to rely on.
42%
Total Score
25
63
The package was first and only released on 2017-01-25, with no releases in the last 12 months, so there’s no observable maintenance cadence. This heavily increases abandonment risk for this specific dependency version.
There were zero commits in the last 3 months and zero active maintainers in that window. That matches the long release gap and reinforces that updates are unlikely.
The artifact includes a README and indicates repo tests are present, which helps basic consumer understanding and regression confidence. The changelog is missing, so there’s less documented change history for future debugging.
Open issues and pull requests are 0, and new activity in the last month is also 0. While not a security problem, it’s consistent with a lack of active maintenance.
No GitHub Actions workflows were analyzed (workflows_total = 0, workflows_analyzed = 0). That means CI/security hygiene can’t be confirmed, though it doesn’t introduce a direct failure signal by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version >=3.3.2 <4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.