Pop Cache Component for Pop PHP Framework
82%
Total Score
83
100
94
75
One contributor made 14 of 15 commits in the last 3 months, creating a real concentration risk. A second contributor is active and the repository is organization-owned, which partly compensates but does not remove the concern.
The repository uses Composer, but no security scanning tool was detected. This is a security-process gap, though it is not evidence that the package is malicious or unmaintained.
No repository security policy was found. That weakens vulnerability-reporting transparency, although active commits, tests, and current releases provide compensating maintenance evidence.
The single analyzed workflow has no top-level token permissions declaration. No write permissions were detected, but explicitly limiting permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
popphp/pop-db Version ^7.0.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.