Package Health

dweeves/magmi

The package includes a README, tests, release notes, and an MIT license. The workflow audit also found a high-confidence unpinned container image, adding maintenance hygiene risk.

Latest 0.7.24PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The latest release was in September 2020, with no releases in the last 12 months; the earlier six-release history shows initial activity but not current maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for years.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while 299 issues and 26 pull requests remain open, indicating unresolved maintenance demand.

Security policycaution

The linked repository has no security policy, leaving reporting and response expectations undocumented; the release notes do document a security fix, which provides some compensating transparency.

Workflow auditcaution

The single workflow was fully analyzed and has no untrusted checkout or script-injection path, but its container image is unpinned with high confidence, weakening build reproducibility.

Vulnerabilities

TitleVersionsSeverity
CVE-2017-7391
dweeves/magmi is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 0.7.22.
0.0.0 - 0.7.22
Medium
CVE-2014-8770
dweeves/magmi is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 0.7.17a.
0.0.0 - 0.7.17a
Critical
CVE-2015-2068
dweeves/magmi is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 0.7.22.
0.0.0 - 0.7.22
Medium
CVE-2015-2067
dweeves/magmi is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 0.7.21.
0.0.0 - 0.7.21
Medium
CVE-2020-5776
dweeves/magmi is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 0.7.24.
0.0.0 - 0.7.24
High

Package versions

Maintainers

Sebastien Bracquemont

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform