The package includes tests, release notes for this version, a clear MIT license, and a small dependency surface. Its workflow has unpinned actions and high-confidence secrets inheritance findings, while the repository has no security policy.
62%
Total Score
50
100
86
83
The latest release was over 2 years ago, and there were no releases in the last 12 months. The package has a long history and nine releases, but current maintenance appears paused.
There were no commits and no active maintainers in the last 3 months. Combined with the old latest release, this is meaningful evidence of paused maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and assurance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This weakens project transparency but is not an abandonment verdict by itself.
The only workflow was fully analyzed and uses read-only permissions, but both action references are unpinned and two high-confidence medium-severity secrets-inherit findings were reported. These are workflow hygiene risks, not a standalone dependency blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/orm Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.