Clear documentation, tests, licensing, and a security contact make adoption easier. The beta label and unpinned workflow actions call for pinning this exact version and reviewing CI exposure.
82%
Total Score
100
100
89
88
Composer build tooling is present, but no security scanning tools were detected; the gap is partly offset by the repository's separate security policy.
This is a prerelease beta, so compatibility may still change; however, only 25% of recent releases are prereleases, limiting the concern to version stability rather than project health.
All five workflows were analyzed with no untrusted checkouts or script-injection counts, and four use read-only permissions. However, all 23 action references are unpinned, while two high-confidence template-injection findings in docker-publish.yml warrant CI review; the low-confidence cache findings are hygiene only.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-6744 bagisto/bagisto is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 2.3.15. | 0.0.0 - 2.3.15 | Medium |
CVE-2026-6745 bagisto/bagisto is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.3.15. | 0.0.0 - 2.3.15 | Low |
CVE-2026-21449 bagisto/bagisto is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 2.3.10. | 0.0.0 - 2.3.10 | High |
CVE-2026-21447 bagisto/bagisto is vulnerable to Improper Access Control in versions 0.0.0 - 2.3.10. | 0.0.0 - 2.3.10 | High |
CVE-2026-21448 bagisto/bagisto is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 2.3.10. | 0.0.0 - 2.3.10 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^8.2 | — | — |
laravel/ai Version ^0.7.0 | — | — |
laravel/ui Version ^4.0 | — | — |
nesbot/carbon Version ^3.0 | — | — |
predis/predis Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.