Documentation is thorough, and the package is easy to trace to its maintained source. One workflow contains a high-confidence condition that always evaluates true, creating a modest automation-hygiene concern.
88%
Total Score
100
100
100
All five workflows were analyzed with no untrusted checkout or script-injection findings, and all 12 action references are pinned. However, a high-confidence finding reports a testing condition that always evaluates true, and two workflows have top-level write permissions; without an untrusted trigger these remain hygiene concerns rather than severe risks.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-57570 backpack/crud is vulnerable to Missing Authorization in versions 7.0.0 - 7.0.47 and 6.0.0 - 6.8.15. | 6.0.0 - 6.8.157.0.0 - 7.0.47 | Medium |
CVE-2026-54182 backpack/crud is vulnerable to Improper Input Validation in versions 4.1.0 - 4.1.72, 5.0.0 - 5.6.2, 6.0.0 - 6.8.13 and 7.0.0 - 7.0.36. | 4.1.0 - 4.1.725.0.0 - 5.6.26.0.0 - 6.8.13 +1 more | High |
CVE-2026-54181 backpack/crud is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 6.8.14 and 7.0.0 - 7.0.38. | 6.0.0 - 6.8.147.0.0 - 7.0.38 | Medium |
CVE-2026-54180 backpack/crud is vulnerable to Authorization Bypass Through User-Controlled Key in versions 6.0.0 - 6.8.14 and 7.0.0 - 7.0.38. | 6.0.0 - 6.8.147.0.0 - 7.0.38 | High |
CVE-2026-54179 backpack/crud is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.0.0 - 6.8.14 and 7.0.0 - 7.0.38. | 6.0.0 - 6.8.147.0.0 - 7.0.38 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.0 | — | — |
backpack/basset Version ^2.0.9 | — | — |
prologue/alerts Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.0|^8.0 | — | — |
laravel/framework Version ^12|^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.