Gestionale open-source per assistenza tecnica e fatturazione elettronica
81%
Total Score
healthy
Healthy overall, supported by active development and project backing; beta status and unpinned workflow actions are the main caveats.
Four Composer lifecycle scripts run during installation or updates. These are relevant operational behavior for a full Laravel application, but the signal alone does not show unsafe or unexpected actions.
Issues and pull requests remain active, with six new issues and four new pull requests in the last month, although only two issues and one pull request were closed or merged.
This is a prerelease despite being on a stable major line, and recent prereleases make up 20% of releases. The release notes explicitly say not to use this version in production, which materially lowers confidence for production adoption.
Both workflows were analyzed successfully with no untrusted checkout, injection, or high-severity findings, and one scopes permissions at job level. However, all 10 analyzed action references are unpinned, leaving avoidable workflow supply-chain exposure.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-44701 devcode-it/openstamanager is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.10.1. | 0.0.0 - 2.10.1 | Low |
CVE-2026-38751 devcode-it/openstamanager is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 2.10-beta. | 0.0.0 - 2.10-beta | High |
CVE-2026-35470 devcode-it/openstamanager is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.10.1. | 0.0.0 - 2.10.1 | High |
CVE-2026-35168 devcode-it/openstamanager is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.10.1. | 0.0.0 - 2.10.1 | High |
CVE-2026-29782 devcode-it/openstamanager is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 2.10.1. | 0.0.0 - 2.10.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
mpdf/mpdf Version ^v8.0.10 | — | — |
league/csv Version ^9.7.0 | — | — |
slim/flash Version ^0.4.0 | — | — |
filp/whoops Version ^2.15.0 | — | — |
voku/stringy Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.