Package Health

devcode-it/openstamanager

Gestionale open-source per assistenza tecnica e fatturazione elettronica

Latest v2.11.1-betaPackagistPackagist

81%

Total Score

healthy

Healthy overall, supported by active development and project backing; beta status and unpinned workflow actions are the main caveats.

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

Four Composer lifecycle scripts run during installation or updates. These are relevant operational behavior for a full Laravel application, but the signal alone does not show unsafe or unexpected actions.

Repo issue activitycaution

Issues and pull requests remain active, with six new issues and four new pull requests in the last month, although only two issues and one pull request were closed or merged.

Version stabilitycaution

This is a prerelease despite being on a stable major line, and recent prereleases make up 20% of releases. The release notes explicitly say not to use this version in production, which materially lowers confidence for production adoption.

Workflow auditcaution

Both workflows were analyzed successfully with no untrusted checkout, injection, or high-severity findings, and one scopes permissions at job level. However, all 10 analyzed action references are unpinned, leaving avoidable workflow supply-chain exposure.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-44701
devcode-it/openstamanager is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.10.1.
0.0.0 - 2.10.1
Low
CVE-2026-38751
devcode-it/openstamanager is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 2.10-beta.
0.0.0 - 2.10-beta
High
CVE-2026-35470
devcode-it/openstamanager is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.10.1.
0.0.0 - 2.10.1
High
CVE-2026-35168
devcode-it/openstamanager is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 2.10.1.
0.0.0 - 2.10.1
High
CVE-2026-29782
devcode-it/openstamanager is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 2.10.1.
0.0.0 - 2.10.1
High

Package versions

Maintainers

DevCode s.r.l.

Direct Dependencies

DependencyLast ReleaseScore
mpdf/mpdf
Version ^v8.0.10
—
—
league/csv
Version ^9.7.0
—
—
slim/flash
Version ^0.4.0
—
—
filp/whoops
Version ^2.15.0
—
—
voku/stringy
Version ^6.0.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform