Clear licensing, tests, release notes, and a security policy make the project transparent. Unpinned workflow actions add a small maintenance risk.
63%
Total Score
83
100
89
67
A pre-autoload-dump install-time script runs during dependency installation, adding execution surface that consumers should understand, though this signal alone is not evidence of abandonment.
The package has existed for about 9 years with 24 releases, but it has had no registry releases in the last 12 months, which raises a maintenance concern.
The repository recorded zero commits and zero active maintainers in the last three months, a significant warning about current development activity.
Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The single workflow was fully analyzed with no injection or high-confidence audit findings, but both action references are unpinned, reducing build reproducibility and supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-52838 alextselegidis/easyappointments is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.5.2. | 0.0.0 - 1.5.2 | Low |
CVE-2026-52841 alextselegidis/easyappointments is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 1.5.2. | 0.0.0 - 1.5.2 | Low |
CVE-2026-52837 alextselegidis/easyappointments is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 1.5.2. | 0.0.0 - 1.5.2 | Medium |
CVE-2026-52839 alextselegidis/easyappointments is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 1.5.2. | 0.0.0 - 1.5.2 | Low |
CVE-2026-52840 alextselegidis/easyappointments is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.5.2. | 0.0.0 - 1.5.2 | Low |
| Dependency | Last Release | Score |
|---|---|---|
jsvrcek/ics Version ^0.8.4 | — | — |
sabre/vobject Version ^4.5 | — | — |
symfony/finder Version ^6.4 | — | — |
gregwar/captcha Version ^1.1.9 | — | — |
monolog/monolog Version ^2.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.