CakePHP 5 plugin that signs users in through the central Rock Software identity provider (OpenID Connect).
64%
Total Score
caution
Usable with caveats: this brand-new package has no track record and uses a proprietary license.
The manifest declares a proprietary license and no license file was detected. This defines usage rights but is a significant adoption and transparency caveat for a package presented as open source.
The package is brand new, with only 2 releases and both published within about 30 minutes, so there is little evidence of sustained maintenance or release stability yet.
There were 0 commits and 0 active maintainers in the last 3 months, but the repository and release are less than a day old, so this is mainly a lack of track record rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security coverage unclear.
The repository has no security policy, so its process for receiving and handling vulnerability reports is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.1 | — | — |
firebase/php-jwt Version ^6.10 || ^7.0 | — | — |
cakephp/migrations Version ^4.0 || ^5.0 | — | — |
cakephp/authentication Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.