The package includes tests, a README, and a declared MIT license, which provide useful baseline transparency. Its single-maintainer project has no security policy and very limited adoption, increasing the cost of relying on it.
44%
Total Score
25
70
50
The latest release was published in March 2021, and there have been no releases in roughly five and a half years. This is strong evidence that maintenance has stopped for a library intended as a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no observed recent work to offset the abandonment risk.
Only one account has registry publish access. The linked project is user-owned rather than organization-backed, so the narrow maintainer base adds continuity risk.
The repository has one star, zero forks, and one watcher, showing very limited external adoption or review. Popularity is only supporting evidence, but it provides little confidence that problems will be noticed quickly.
No security policy is present in the repository. For a library with several runtime dependencies, this is a transparency and response-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/orm Version 3.* | — | — |
psr/container Version ^1.0 | — | — |
bramus/ansi-php Version ^3.0 | — | — |
cakephp/utility Version 3.* | — | — |
cakephp/collection Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.