The license metadata conflicts with a bundled LGPL-2.1 file, and the project has no security scanning or policy. A substantial README, tests, release notes, and an unarchived repository provide useful transparency, but they do not offset the age.
38%
Total Score
50
50
57
67
The latest release was published about 10 years ago, with no releases in the last 12 months; this is strong evidence of abandonment for a framework application skeleton.
Nine runtime dependencies make the application skeleton rely on a moderately broad dependency set, increasing maintenance surface; no provided evidence shows that these dependencies are currently maintained.
The package declares MIT and includes a license file, but the detected LGPL-2.1 text appears at webroot/js/tinymce/license.txt and is not the package declaration; this mismatch warrants license review.
The package runs post-autoload-dump, post-create-project-cmd, and post-install-cmd scripts, increasing installation complexity and execution exposure even though this is common for application skeletons.
The linked repository is owned by an organization, which provides some backing context, but the observed release and repository activity still indicates an inactive project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ~3.2 | — | — |
cakephp/migrations Version ~1.0 | — | — |
friendsofcake/search Version ^1.2 | — | — |
crabstudio/authenticate Version ^1.0 | — | — |
wyrihaximus/minify-html Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.