concrete5/core 9.5.4 appears to be a mature, actively maintained, stable release: it has 88 releases over more than 9 years, 11 releases in the last 12 months, a recent release, substantial repository commit activity from 15 active maintainers, an unarchived organization-owned repository, tests and a changelog, and no registry deprecation or install-time lifecycle scripts. The main concerns are the large runtime dependency surface, absence of repository security-scanning tooling and a security policy, limited recent issue and pull-request activity, and the linked repository not matching the package name with no confirmed README mention; these warrant verification of repository provenance and ongoing support but do not outweigh the strong maintenance evidence.
86%
Total Score
88
50
88
83
The package declares 91 runtime dependencies and no development dependencies, creating a large transitive maintenance and compatibility surface. This is a genuine adoption concern for a framework of this size, although the broad runtime functionality makes a sizable dependency set understandable.
There were no new or closed issues or pull requests in the last month, and no pull requests were open; this indicates limited recent issue-tracker activity, though the null open-issues count prevents a stronger conclusion.
The repository name does not match concrete5/core, and the collected data does not confirm that the package is mentioned in its README. This provenance mismatch should be verified before adoption, even though subpackages in monorepos can legitimately use different names.
Composer is used as a build tool, but no security-scanning tools are detected. The missing scanning evidence is a supply-chain hygiene gap, not evidence that the package is malicious.
The repository has no published security policy, reducing transparency about vulnerability reporting and response procedures.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-21829 concrete5/core is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8. | 0.0.0 - 8.5.89.0.0 - 9.1.0 | High |
CVE-2022-30120 concrete5/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8. | 0.0.0 - 8.5.89.0.0 - 9.1.0 | Low |
CVE-2022-30117 concrete5/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8. | 0.0.0 - 8.5.89.0.0 - 9.1.0 | Critical |
CVE-2021-22968 concrete5/core is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 0.0.0 - 8.5.7. | 0.0.0 - 8.5.7 | High |
CVE-2021-22970 concrete5/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 8.5.7. | 0.0.0 - 8.5.7 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version 3.11.3|^3.26 | — | — |
league/csv Version ^9.7.1 | — | — |
league/url Version ~3.3.5 | — | — |
punic/punic Version ^3.0.1 | — | — |
doctrine/orm Version ^2.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.