Usable with caveats: the package is licensed, documented, tested, and backed by a matching organization repository, but it has had no registry release since July 2017 and no commits in the last three months. Expect compatibility and maintenance risk for modern CakePHP projects.
58%
Total Score
50
100
83
83
The repository recorded zero commits and zero active maintainers in the last three months, a strong sign that maintenance has stalled.
The package has six releases but none in the last 12 months, with the latest release published in July 2017. This long release gap is a meaningful maintenance and compatibility concern.
There are six open issues and one open pull request, while no issues or pull requests were opened or closed in the last month. This indicates unresolved and inactive project management.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a transparency gap, though it is less significant than the demonstrated source and test structure.
The linked repository is not archived, and it was last pushed in December 2019. However, that push is still several years old relative to the assessed release context, so it does not remove the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ~3.1 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.