Healthy and suitable to depend on. It has a long, active release history, current commits from three contributors, tests, documentation, and reproducible project tooling. Review the repository’s incomplete workflow permission settings and lack of a security policy before adopting it in a sensitive environment.
88%
Total Score
88
100
100
80
The top contributor made 80% of the last three months’ commits, which creates some concentration risk. Two additional contributors remained active, partly offsetting that risk.
No repository security policy was found, leaving disclosure and response procedures unclear. This is a transparency gap, though it is not evidence of abandonment.
One workflow lacks top-level permissions and another declares write access. The workflows show no dangerous execution patterns, but least-privilege settings are not consistently evident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/bake Version ^3.2.0 | — | — |
sebastian/diff Version ^6.0 || ^7.0 || ^8.0 || ^9.0 | — | — |
cakephp/cakephp Version ^5.1.5 | — | — |
nikic/php-parser Version ^5.7 | — | — |
phpstan/phpdoc-parser Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.