The package is licensed, documented, and backed by a repository with tests. Its small release history, absent security tooling, and unpinned workflow actions limit confidence in long-term maintenance and build hygiene.
66%
Total Score
75
100
78
75
The package is young at 287 days with four releases, all within the last 12 months; the short history and bursty cadence provide limited evidence of mature maintenance.
There were zero commits and zero active maintainers in the last three months. Although the repository was pushed recently and the package has only four releases, this is a meaningful sign of currently quiet maintenance.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but the package is young and popularity alone does not establish a health problem.
Composer build tooling is present, but no security scanning tools are configured. That leaves an avoidable gap in repository transparency and automated supply-chain hygiene.
The repository has no security policy. This is a maintenance and disclosure gap, though it is not severe enough on its own to make the release unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/queue Version ^2.0 | — | — |
cakephp/cakephp Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.