A substantial README, repository tests, and frequent releases make the package easier to evaluate and integrate. Its 0.x version signals possible API change, so pinning and upgrade testing are prudent.
70%
Total Score
75
83
50
All 322 recent commits came from one contributor, leaving limited visible handoff capacity and increasing continuity risk.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear for adopters.
Version 0.13.1 is not a stable major release, so consumers may face compatibility changes despite the absence of prereleases.
The audit completed successfully, but all four action references are unpinned and high-confidence template-injection findings were reported in both workflows; no untrusted checkout or dangerous trigger was found to amplify them.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-49262 aimeos/pagible is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 0.10.4. | 0.0.0 - 0.10.4 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aimeos/pagible-ai Version ~0.13 | — | — |
aimeos/pagible-mcp Version ~0.13 | — | — |
aimeos/pagible-core Version ~0.13 | — | — |
aimeos/pagible-admin Version ~0.13 | — | — |
aimeos/pagible-theme Version ~0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.