Image upload for CakePHP 4
52%
Total Score
caution
Usable with caveats: no releases or commits since September 2022.
The package has 16 releases since September 2020, but none in the last four years; the long release gap is a meaningful abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly four years without a release and weakening maintenance confidence.
Composer build tooling is present, but no security-scanning tool is reported; this is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy, leaving users without a documented reporting process; this matters for an upload-handling library.
The single workflow was fully analyzed with no dangerous sinks or audit findings, but all three action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^4.1.0 | — | — |
imagine/imagine Version ^1.2 | — | — |
composer/composer Version 2.2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.