The package includes clear usage documentation, release notes, repository tests, and a matching MIT license. Its maintenance record is still unproven, and CI uses four unpinned actions; organization backing helps, but all recent commits come from one contributor.
68%
Total Score
67
88
67
This is the first release and the package is only 0 days old, so there is no release history yet to demonstrate sustained maintenance.
One contributor made all 7 recent commits, creating concentration risk. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
Seven commits in the last 3 months show active initial development, but the short observation window provides limited evidence of long-term maintenance.
The repository has no security policy, which is a transparency gap for a package handling contact-form data, though the repository does use Dependabot scanning.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all 4 action references are unpinned, leaving CI exposed to action changes over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.