The repository is a complete, tested CakePHP skeleton with a substantial README, matching source project, and clear MIT licensing. Its single release and lack of recent commits leave maintenance and compatibility uncertain for a new dependency.
38%
Total Score
75
79
100
This package has only one release, published roughly 11 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk, despite the repository remaining available.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap. This materially reduces confidence that defects or compatibility issues will be addressed.
Composer build tooling is present, which fits this Packagist package. No security scanning tools were observed, but that is a secondary hygiene gap beside the much older maintenance history.
The assessed version is v0.2.0 rather than a stable major release, so its API and behavior may be less mature. The absence of a prerelease flag provides only limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
gourmet/robo Version dev-master | — | — |
gourmet/faker Version ~1.0 | — | — |
cakephp/cakephp Version ~3.0 | — | — |
cakephp/migrations Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.