Package Health

concrete5/core

concrete5/core 9.5.4 appears to be a mature, actively maintained, stable release: it has 88 releases over more than 9 years, 11 releases in the last 12 months, a recent release, substantial repository commit activity from 15 active maintainers, an unarchived organization-owned repository, tests and a changelog, and no registry deprecation or install-time lifecycle scripts. The main concerns are the large runtime dependency surface, absence of repository security-scanning tooling and a security policy, limited recent issue and pull-request activity, and the linked repository not matching the package name with no confirmed README mention; these warrant verification of repository provenance and ongoing support but do not outweigh the strong maintenance evidence.

Latest 9.5.4PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 91 runtime dependencies and no development dependencies, creating a large transitive maintenance and compatibility surface. This is a genuine adoption concern for a framework of this size, although the broad runtime functionality makes a sizable dependency set understandable.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and no pull requests were open; this indicates limited recent issue-tracker activity, though the null open-issues count prevents a stronger conclusion.

Repo package mentioncaution

The repository name does not match concrete5/core, and the collected data does not confirm that the package is mentioned in its README. This provenance mismatch should be verified before adoption, even though subpackages in monorepos can legitimately use different names.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are detected. The missing scanning evidence is a supply-chain hygiene gap, not evidence that the package is malicious.

Security policycaution

The repository has no published security policy, reducing transparency about vulnerability reporting and response procedures.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-21829
concrete5/core is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8.
0.0.0 - 8.5.89.0.0 - 9.1.0
High
CVE-2022-30120
concrete5/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8.
0.0.0 - 8.5.89.0.0 - 9.1.0
Low
CVE-2022-30117
concrete5/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 9.0.0 - 9.1.0 and 0.0.0 - 8.5.8.
0.0.0 - 8.5.89.0.0 - 9.1.0
Critical
CVE-2021-22968
concrete5/core is vulnerable to Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in versions 0.0.0 - 8.5.7.
0.0.0 - 8.5.7
High
CVE-2021-22970
concrete5/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 8.5.7.
0.0.0 - 8.5.7
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version 3.11.3|^3.26
league/csv
Version ^9.7.1
league/url
Version ~3.3.5
punic/punic
Version ^3.0.1
doctrine/orm
Version ^2.13

Weekly Downloads

Info

Last Published
12 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform