Package Health

easycorp/easyadmin-bundle

It also includes tests, release notes, a security policy, and a clear MIT license. Workflow images are unpinned, leaving a contained build-reproducibility concern.

Latest v5.6.1PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

All four workflows were analyzed without untrusted checkouts or script injection, but both detected high-confidence findings concern unpinned container images and all 21 action references are unpinned; this weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-56487
easycorp/easyadmin-bundle is vulnerable to Authorization Bypass in versions 4.0.0 - 4.29.15 and 5.0.0 - 5.5.0.
4.0.0 - 4.29.155.0.0 - 5.5.0
High
CVE-2026-54087
easycorp/easyadmin-bundle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.0.13.
5.0.0 - 5.0.13
High
AIKIDO-2026-10519 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
easycorp/easyadmin-bundle is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.1 - 4.29.5 and 5.0.0 - 5.0.5.
0.0.1 - 4.29.55.0.0 - 5.0.5
High
AIKIDO-2024-10379
easycorp/easyadmin-bundle is vulnerable to Cross-site Scripting (XSS) in versions 3.4.0 - 4.8.9.
3.4.0 - 4.8.9
Low
AIKIDO-2024-10378 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
easycorp/easyadmin-bundle is vulnerable to Cross-site Scripting (XSS) in versions 3.5.0 - 4.9.5.
3.5.0 - 4.9.5
Low

Package versions

Maintainers

Project Contributors

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.23
—
—
symfony/uid
Version ^6.4.32|^7.0|^8.0
—
—
doctrine/orm
Version ^2.20|^3.6
—
—
symfony/form
Version ^6.4.32|^7.0|^8.0
—
—
symfony/intl
Version ^6.4.32|^7.0|^8.0
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform