The MIT license, focused dependency set, clear README, and release notes make the package straightforward to inspect and integrate. Its last registry release was nearly seven years ago, the assessed version remains a prerelease, and recent repository activity is absent, leaving maintenance risk high.
44%
Total Score
50
100
75
75
The package has 18 releases but none in the last 12 months; its latest registry release was nearly seven years ago, which is a substantial abandonment concern.
There were no commits and no active maintainers in the last three months, consistent with a project that is no longer actively maintained.
Composer is used for builds, but no security scanning tools are present; this is a modest repository hygiene gap rather than evidence of unfitness by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; this adds a transparency concern for an authorization-related plugin.
The assessed release is a prerelease, and prereleases make up about 44% of recent releases, reducing confidence that this is a mature stable target.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^4.0.0-RC1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.