The MIT license, tests, and organization-owned repository improve transparency. There is no security policy, and the install hook adds a small operational review burden.
42%
Total Score
50
71
50
The package has had no release in over eight years and none in the last 12 months, making abandonment a substantial dependency risk. Its four-release history is limited but not inherently disqualifying.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and leaving little evidence of current maintenance capacity.
A post-autoload-dump install lifecycle script runs during Composer installation, adding a small operational review burden. The signal does not show that the script is harmful.
Zero stars and forks provide no meaningful community support signal. Popularity is only supporting evidence, but it reinforces the maintenance concern when combined with the inactive release and commit history.
The repository uses Make and Composer, showing basic build tooling, but it has no security scanning. The tooling is adequate for a small PHP application while the missing scanning is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cake-cms/core Version ~1.2 | — | — |
cake-cms/config Version ~1.0 | — | — |
cakephp/cakephp Version ~3.5 | — | — |
cake-cms/backend Version ~1.1 | — | — |
cake-cms/frontend Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.