shouldiuse.io

VERDICT

Should I use CakePHP?

Open-source PHP MVC framework for building web applications faster with less code. - cakephp.org

Depends. Choose CakePHP only if you have PHP developers building a custom web app — it's free, mature, and well-structured. Non-developers, no-code buyers, and non-PHP teams should skip it entirely.

Confidence

Medium. Based on 14 public sources. Review snippets were heavily truncated, so sentiment is directional rather than scored.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • PHP development teams
  • Custom CRUD web apps
  • Convention-over-configuration fans
  • Legacy CakePHP codebases

Not for

  • Non-developers wanting a website — this is code, not a product
  • Teams without PHP skills; pick a no-code tool instead
  • Buyers needing vendor support contracts or SLAs
  • Greenfield teams wanting the biggest talent pool — Laravel wins

Gotchas - check before you buy

high

Many live deployments leak debug errors and config warnings publicly.

high

Guess: upgrading old 2.x/3.x apps to current 5.x is a costly rewrite.

medium

No vendor support: you depend on community forums and your own developers.

Pros and cons

Pros

  • Free and open-source; zero license fees.
  • MVC structure makes apps simpler, faster, with less code.
  • Users consistently praise the ease of use.
  • Actively maintained with current 5.x releases.
  • One of the oldest, longest-running PHP frameworks.

Cons

  • Guess: smaller ecosystem and hiring pool than Laravel.
  • Past security advisories on record, including IP spoofing.
  • No vendor support; help means community forums.
  • Framework only — you still pay developers to build everything.

Sources & method

Analyzed 9/20/2026 - 9 sources - Free security page with reporting process; two advisories from 2016 era.

official x3review x3security x3
  • IP spoofing vulnerability in CakePHP 3.2.4, Debug-mode-dependent IP spoofing issue disclosed May 2016.
  • Multiple vulnerabilities, SSD Advisory disclosed multiple CakePHP vulnerabilities to Beyond Security's SecuriTeam.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 9

    Sources

  • Analyzed

  • Value for money: 5/5. Free, open-source, no licensing cost
  • Ease of use: 4/5. Reviewers consistently praise ease of use
  • Feature depth: 4/5. Full MVC stack, conventions, less code
  • Support quality: 2/5. Community forums only, no vendor SLA
  • Security posture: 3/5. Security page exists; past advisories on record
  • $0 Price Open-source, no license fees
  • 5.x Current major version GitHub app skeleton branch
  • Positive Review sentiment G2 and PeerSpot reviewers
  • 2+ Public advisories 2016 IP spoofing plus multi-vulnerability disclosure

Pricing

Open source

$0

  • Full framework
  • Community support
  • MIT-style open-source use

Security

Free security page with reporting process; two advisories from 2016 era.

  • IP spoofing vulnerability in CakePHP 3.2.4Debug-mode-dependent IP spoofing issue disclosed May 2016.⁴
  • Multiple vulnerabilitiesSSD Advisory disclosed multiple CakePHP vulnerabilities to Beyond Security's SecuriTeam.⁵

What users say

Reviewers on G2 and PeerSpot describe it as an easy-to-use, powerful PHP framework, though review snippets surfaced are short.

“Users consistently praise the ease...”
G2 reviews
“CakePHP is a powerful PHP framework...”
PeerSpot review

Companies that use it

  • ASID (American Society of Interior Designers)
  • Classera
  • Braquets
  • ZoneMinder
Full analysis

Based on 14 public sources. Review snippets were heavily truncated, so sentiment is directional rather than scored.

Free, mature open-source PHP MVC framework. Great for PHP devs; useless if you don't code. Laravel has the bigger ecosystem.

Methodology

Based on 14 public sources. Review snippets were heavily truncated, so sentiment is directional rather than scored.

Sources

  1. official
  2. official
  3. security
  4. security
  5. security
  6. review
  7. review
  8. review
  9. CakePHP community forumdiscourse.cakephp.org
    official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.