Usable with caveats: it is a licensed, clearly identified package with tests in the repository, recent releases, and organizational backing. However, the repository shows no commits in the last three months and lacks security-policy and workflow permission hardening.
68%
Total Score
83
50
89
67
Six runtime dependencies, including CakePHP framework and queue components, create a meaningful dependency surface but are consistent with a multi-channel notification plugin.
The repository has zero commits and zero active maintainers in the last three months. Although it was pushed recently and has a recent release, the observed development activity is still thin for a package with an ongoing release history.
The repository has only 2 stars, 0 forks, and 0 watchers, so there is little external adoption evidence. Popularity is supporting evidence, so this lowers confidence in maturity rather than making the package unfit.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap in the repository.
The repository has no security policy, which reduces transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/queue Version ^2.2 | — | — |
cakephp/cakephp Version ^5.1 | — | — |
cakephp/authorization Version * | — | — |
cakephp/authentication Version * | — | — |
crustum/plugin-manifest Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.