It has a usable README, tests, and a matching source tree. However, the single registry maintainer and absent security policy leave little evidence of ongoing stewardship.
15%
Total Score
0
42
50
Packagist marks the entire package as abandoned, with no replacement identified. This is a severe adoption risk beyond a warning limited to one release.
The package has 17 releases but none in the last 12 months; its latest release was in December 2023, about 2 years and 10 months ago. Earlier release activity does not compensate for the prolonged gap.
The repository recorded zero commits and zero active maintainers during the last 3 months. This confirms the lack of current maintenance capacity.
The linked repository is archived, and its last push was about 2 years and 9 months ago. Archived source strongly indicates that maintenance and issue response have ended.
The package declares MIT and includes license files, so it is licensed; however, artifact license detection also found Apache-2.0, which is not covered by the declaration and warrants review of bundled components.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.0 | — | — |
cakephp/migrations Version ^4.1 | — | — |
cakephp/authorization Version ^3.0 | — | — |
cakephp/authentication Version ^3.0 | — | — |
cakephp/plugin-installer Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.