Package Health

aimeos/ai-cms-grapesjs

The package includes a substantial README, repository tests, stable releases, and no install-time scripts. Its maintenance process has limited recent activity, no security policy, and a license-file mismatch that should be resolved.

Latest 2026.10.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The package declares LGPL-3.0, while the artifact license file was detected as LGPL-2.1; although both the artifact and repository contain license files, the mismatch reduces clarity.

Repo bus factorcaution

All two recent commits came from one contributor, leaving maintenance dependent on a single active contributor. The repository owner is recorded as a user rather than an organization, so no organizational handoff is shown.

Repo commit activitycaution

Only two commits were recorded in the last three months, with one active maintainer. This is current but thin activity for a package with ongoing releases.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools were detected. This is a transparency and hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not by itself evidence that the package is unsafe.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-66468
aimeos/ai-cms-grapesjs is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2021.04.1 - 2021.10.8, 2022.04.1 - 2022.10.9, 2023.04.1 - 2023.10.15, 2024.04.1 - 2024.10.8 and 2025.04.1 - 2025.10.2.
2021.04.1 - 2021.10.82022.04.1 - 2022.10.92023.04.1 - 2023.10.15 +2 more
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
aimeos/sanitizer
Version ~0.4
—
—
aimeos/aimeos-core
Version 2026.10.*
—
—
aimeos/ai-admin-jqadm
Version 2026.10.*
—
—
aimeos/ai-client-html
Version 2026.10.*
—
—
aimeos/ai-client-jsonapi
Version 2026.10.*
—
—

Weekly Downloads

Info

Last Published
19 hours ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform