Package Health

bolt/core

The project has regular releases, recent commits from four contributors, tests, a changelog, and a security policy. The beta target and broad dependency set deserve extra care when upgrading.

Latest 5.2.0-beta.24.1PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 82 runtime dependencies, creating substantial transitive maintenance and upgrade exposure for adopters.

Lifecycle scriptscaution

post-install-cmd and post-update-cmd run during Composer operations, adding execution during installation and updates. This is a genuine supply-chain hygiene concern for a dependency with a large runtime footprint.

Repo toolingcaution

The project uses Composer and Make, but no security-scanning tool was detected. That is a modest transparency and hygiene gap rather than evidence of abandonment.

Version stabilitycaution

This release is a beta while the latest version is a stable 6.1.8, so the assessed target is less settled than the current stable line.

Workflow auditcaution

All 43 action references are unpinned, which weakens build reproducibility and supply-chain control. The audit also found high-confidence template-injection patterns in the release workflow, but no untrusted checkout or script-injection trigger was reported, so those findings remain hygiene concerns rather than standalone severe risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-137351 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
bolt/core is vulnerable to Open Redirect in versions 4.0.0 - 6.1.6.
4.0.0 - 6.1.6
Medium
AIKIDO-2026-348054 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
bolt/core is vulnerable to Cross-Site Scripting (XSS) in versions 5.2.0 - 6.1.6.
5.2.0 - 6.1.6
Medium
AIKIDO-2026-965926
bolt/core is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 6.1.6.
0.0.1 - 6.1.6
Medium
CVE-2021-40219
bolt/core is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 4.2.
0.0.0 - 4.2
High
CVE-2021-27367
bolt/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.1.13.
0.0.0 - 4.1.13
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.3
—
—
nelexa/zip
Version ^3.3 || ^4.0
—
—
bolt/common
Version ^3.0.5
—
—
embed/embed
Version ^3.4
—
—
doctrine/orm
Version ^2.10
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform