Package Health

cachethq/cachet

An open source status page system, for everyone.

Latest v2.4.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Release historydanger

The latest registry release was on November 7, 2023, with no releases in the last 12 months; this indicates the assessed line is no longer receiving package updates.

Dependency profilecaution

The release declares 27 runtime dependencies, including a substantial framework and service integration stack, which increases upgrade and compatibility burden.

Lifecycle scriptscaution

The package runs post-autoload-dump, post-create-project-cmd, and post-root-package-install scripts, increasing install-time execution surface and maintenance responsibility.

Workflow auditcaution

All four workflows were analyzed with no reported audit findings or untrusted-checkout sinks. However, 12 of 13 action references are unpinned and two workflows grant top-level write permissions, creating avoidable build-integrity and permission hygiene concerns.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-43661
cachethq/cachet is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 2.4.
0.0.0 - 2.4
Critical
CVE-2021-39172
cachethq/cachet is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.0 - 2.5.1.
0.0.0 - 2.5.1
High
CVE-2021-39165
cachethq/cachet is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.3.18.
0.0.0 - 2.3.18
High
CVE-2021-39173
cachethq/cachet is vulnerable to Incorrect Type Conversion or Cast in versions 0.0.0 - 2.5.1.
0.0.0 - 2.5.1
High
CVE-2021-39174
cachethq/cachet is vulnerable to Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in versions 0.0.0 - 2.5.0.
0.0.0 - 2.5.0
High

Package versions

Maintainers

James Brooks
Graham Campbell
Joseph Cohen

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^2.13
—
—
nexmo/client
Version ^1.5
—
—
alt-three/bus
Version ^4.1
—
—
doctrine/dbal
Version 2.9.*
—
—
predis/predis
Version ^1.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform