cakephp-essentials
78%
Total Score
healthy
Healthy release with caveats: active maintenance outweighs its single-maintainer and unpinned-action risks.
The repository is owned by an individual rather than an organization, so the one-person contributor base represents a real continuity risk rather than normal organization publishing hygiene.
One contributor made all 20 commits in the last 3 months, giving the project a concentrated bus factor. The active release cadence compensates for abandonment concerns only partly.
The repository recorded 20 commits in the last 3 months, showing active development. However, all activity came from one active maintainer, so continuity depends heavily on that person.
No repository security policy was found. This is a modest transparency gap for a library, but it is outweighed by the active maintenance, tests, and clear licensing.
The single workflow has read-only permissions and no untrusted checkouts, injection findings, or audit failures. However, all 12 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
axllent/jquery Version ~3.7|~4.0 | — | — |
twbs/bootstrap Version ~5.3 | — | — |
cakephp/cakephp Version ^5.2 | — | — |
friendsofcake/bootstrap-ui Version ^5.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.