Clear licensing, tests, release notes, and a modest dependency set support predictable integration. The organization-backed repository is active, but recent work is concentrated in two contributors and lacks a security policy.
84%
Total Score
88
100
100
83
Two contributors were active in the last 3 months, but one made about 91% of the commits. Organizational backing partly compensates, yet recent implementation knowledge remains concentrated.
The repository has no SECURITY.md or other detected security policy. For a core platform component handling data access, this is a transparency and vulnerability-reporting gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-55988 dreamfactory/df-core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.0.4. | 0.0.0 - 1.0.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0|^7.0 | — | — |
tymon/jwt-auth Version ^2.1.0 | — | — |
laravel/helpers Version ^1.8 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
dreamfactory/df-system Version ~0.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.