Clear licensing, documentation, tests, release notes, and a small runtime dependency set support adoption. The source project is organized and actively maintained, but publishing has lagged behind repository work and maintenance is concentrated in one contributor.
70%
Total Score
83
100
88
83
The package has 19 releases since 2016, but no registry release in the last 12 months; this lowers confidence in timely published maintenance despite recent repository activity.
All six recent commits came from one contributor, creating maintenance concentration; organization backing helps with handoff potential but does not provide evidence of a second active contributor.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and assurance gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all seven action references are unpinned, weakening build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.