A clear license, matching repository, and release notes improve transparency. Security scanning and a security policy are absent, while the small project footprint offers little resilience.
38%
Total Score
50
72
50
The package has had no releases in the last 12 months, and its latest release was published in October 2018 despite being over 10 years old. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This materially lowers confidence in ongoing maintenance.
The repository has only 3 stars and 4 forks, indicating a small project footprint and limited visible community support. Popularity is supporting evidence, but this increases resilience concerns alongside the inactive maintenance signals.
Composer is used as the build tool, but no security-scanning tool is present. That is a maintenance and assurance gap, though it is not severe on its own.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap for a CMS component.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/plugin-installer Version * | — | — |
codekanzlei/cake-cktools Version 2.* | — | — |
codekanzlei/cake-attachments Version * | — | — |
codekanzlei/cake-model-history Version * | — | — |
codekanzlei/cake-frontend-bridge Version v2.0.0-rc3 as 1.4.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.