The release is documented, licensed, tested, and has a focused dependency profile. Its small maintainer base and missing security policy add modest upkeep risk for a plugin that has seen little recent activity.
58%
Total Score
50
100
88
83
Only one registry account has publish access. Because the repository owner is an individual rather than an organization, this indicates a thin publishing and continuity base.
The registry namespace and repository owner both identify the same individual account, providing consistent ownership evidence. It does not provide the continuity of organization backing.
The package has only 4 releases since September 2014, with no releases in the last 12 months and a median interval of about 3.4 years. The long history helps establish maturity, but the current cadence is weak.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the last repository push in January 2024, this is the clearest evidence of limited current maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.