The MIT license, tests, README, and release notes provide useful transparency for adopting the application skeleton. There is no security policy or security scanning, leaving maintenance and response practices unclear.
42%
Total Score
64
75
This package has only one release, published about 10 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a backend application skeleton.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than a verdict, but these counts provide no sign of an active user or contributor community.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools are configured. That leaves automated detection of dependency or build issues weaker.
The repository is not archived, but it was last pushed about 10 years ago. The unarchived status is reassuring administratively, while the long period without repository activity remains a maintenance concern.
The repository has no security policy. For a backend application skeleton, this reduces transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ~3.2 | — | — |
cakephp/migrations Version ~1.0 | — | — |
cakephp/plugin-installer Version * | — | — |
quankim/cakephp-jwt-auth Version @dev | — | — |
mobiledetect/mobiledetectlib Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.