Feedback or bugreport (with screenshot!) tab option in your CakePHP application. Data can be posted directly to Mantis, E-mail, Github issues, filesystem, etc.
78%
Total Score
healthy
Healthy, supported by regular releases and a maintained, matching source repository.
One contributor made all commits in the last 3 months. Because the repository owner is an individual rather than an organization, this creates a meaningful continuity risk.
Only one commit was recorded in the last 3 months, which is limited activity, though the recent release history shows the project has not stopped evolving.
Composer build tooling is present, but no security-scanning tool was detected. The absence lowers security-process transparency without showing abandonment by itself.
The repository has no security policy, leaving the project's vulnerability-reporting process unclear. The documented security fixes in this release provide some compensating evidence but do not replace a policy.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but its container image is high-confidence and unpinned; all 7 action references are also unpinned. This is a workflow hygiene and reproducibility concern, not a standalone adoption blocker.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10842 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dereuromark/cakephp-feedback is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 2.1.0. | 0.0.1 - 2.1.0 | Critical |
AIKIDO-2025-10841 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dereuromark/cakephp-feedback is vulnerable to Path Traversal in versions 0.0.1 - 2.1.0. | 0.0.1 - 2.1.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.