The project has regular releases, recent commits from four contributors, tests, a changelog, and a security policy. The beta target and broad dependency set deserve extra care when upgrading.
70%
Total Score
100
50
88
67
The package declares 82 runtime dependencies, creating substantial transitive maintenance and upgrade exposure for adopters.
post-install-cmd and post-update-cmd run during Composer operations, adding execution during installation and updates. This is a genuine supply-chain hygiene concern for a dependency with a large runtime footprint.
The project uses Composer and Make, but no security-scanning tool was detected. That is a modest transparency and hygiene gap rather than evidence of abandonment.
This release is a beta while the latest version is a stable 6.1.8, so the assessed target is less settled than the current stable line.
All 43 action references are unpinned, which weakens build reproducibility and supply-chain control. The audit also found high-confidence template-injection patterns in the release workflow, but no untrusted checkout or script-injection trigger was reported, so those findings remain hygiene concerns rather than standalone severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-137351 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. bolt/core is vulnerable to Open Redirect in versions 4.0.0 - 6.1.6. | 4.0.0 - 6.1.6 | Medium |
AIKIDO-2026-348054 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. bolt/core is vulnerable to Cross-Site Scripting (XSS) in versions 5.2.0 - 6.1.6. | 5.2.0 - 6.1.6 | Medium |
AIKIDO-2026-965926 bolt/core is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 6.1.6. | 0.0.1 - 6.1.6 | Medium |
CVE-2021-40219 bolt/core is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 4.2. | 0.0.0 - 4.2 | High |
CVE-2021-27367 bolt/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.1.13. | 0.0.0 - 4.1.13 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3 | — | — |
nelexa/zip Version ^3.3 || ^4.0 | — | — |
bolt/common Version ^3.0.5 | — | — |
embed/embed Version ^3.4 | — | — |
doctrine/orm Version ^2.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.