Tests, documentation, release notes, and a small runtime dependency set support straightforward adoption. Maintenance is concentrated in one contributor, and the workflow’s seven action references are unpinned.
73%
Total Score
50
100
94
50
One contributor made all commits in the last 3 months, giving the project a concentrated maintenance base. The package is still actively released, but continuity depends heavily on that maintainer.
The repository had 1 commit in the last 3 months, showing some recent activity but a low maintenance pace. The recent release history partly offsets this concern.
Composer build tooling is present, but no security scanning tools were detected. The absence of scanning is a hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a process weakness rather than a direct dependency failure.
The single workflow was fully analyzed with no untrusted checkout, injection, or audit findings, but all 7 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.