The organization backing and matching repository improve traceability. Seven of eight workflow actions are unpinned, and no security policy or scanning tool is present.
67%
Total Score
67
86
75
This is the package's first release, published today, so there is no release history or cadence to demonstrate sustained maintenance.
One contributor accounts for all recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository has only two commits in the last three months, all within a single active contributor, which is too little history to establish durable maintenance.
Composer build tooling is present, but no security-scanning tool was detected, leaving the project's security hygiene less independently evidenced.
The repository has no security policy, so consumers lack a documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/queue Version ^2.3 | — | — |
cakephp/cakephp Version ^5.3 | — | — |
symfony/polyfill-php84 Version ^1.31 | — | — |
crustum/plugin-manifest Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.