Its small audience and one-person publishing base limit independent oversight, while recent commit activity is quiet. Clear documentation, tests, licensing, and a focused dependency set provide useful support for adoption.
72%
Total Score
50
94
67
Only one account has registry publishing access. The repository is user-owned rather than organization-backed, so there is limited visible publishing redundancy.
The repository recorded zero commits and zero active maintainers in the last three months. Although releases continued, this is a meaningful sign of limited current development activity.
The repository has only 3 stars and no forks, which limits evidence of broad community review or an independent support base. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, though the repository does use GitGuardian scanning.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 6 action references are unpinned, leaving a modest reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/authentication Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.