An open source status page system, for everyone.
42%
Total Score
100
50
88
67
The latest registry release was on November 7, 2023, with no releases in the last 12 months; this indicates the assessed line is no longer receiving package updates.
The release declares 27 runtime dependencies, including a substantial framework and service integration stack, which increases upgrade and compatibility burden.
The package runs post-autoload-dump, post-create-project-cmd, and post-root-package-install scripts, increasing install-time execution surface and maintenance responsibility.
All four workflows were analyzed with no reported audit findings or untrusted-checkout sinks. However, 12 of 13 action references are unpinned and two workflows grant top-level write permissions, creating avoidable build-integrity and permission hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-43661 cachethq/cachet is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 2.4. | 0.0.0 - 2.4 | Critical |
CVE-2021-39172 cachethq/cachet is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.0 - 2.5.1. | 0.0.0 - 2.5.1 | High |
CVE-2021-39165 cachethq/cachet is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.3.18. | 0.0.0 - 2.3.18 | High |
CVE-2021-39173 cachethq/cachet is vulnerable to Incorrect Type Conversion or Cast in versions 0.0.0 - 2.5.1. | 0.0.0 - 2.5.1 | High |
CVE-2021-39174 cachethq/cachet is vulnerable to Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in versions 0.0.0 - 2.5.0. | 0.0.0 - 2.5.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.13 | — | — |
nexmo/client Version ^1.5 | — | — |
alt-three/bus Version ^4.1 | — | — |
doctrine/dbal Version 2.9.* | — | — |
predis/predis Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.