Package Health

exceedone/exment

Management for Product, Client, Contracts, Subscription, ...

Latest v6.2.14PackagistPackagist

68%

Total Score

caution

Usable with caveats: recent activity is concentrated in one contributor, despite regular releases and organizational backing.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

All 3 recent commits came from one contributor, giving a 100% top-contributor share. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.

Repo commit activitycaution

Only 3 commits were made in the last 3 months, indicating modest recent development activity despite the current release. The recent release cadence partly offsets this, but does not remove the maintenance concern.

Repo issue activitycaution

The repository has 60 open issues and 9 open pull requests; in the last month it received 4 issues but closed none, while merging 2 pull requests. This suggests some backlog and limited recent issue resolution.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. For a large web application, that leaves a meaningful maintenance and vulnerability-management gap.

Security policycaution

The repository has no security policy or documented security-reporting path. This reduces transparency for handling vulnerabilities in an application that manages business information.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-38080
exceedone/exment is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.0.3 and 0.0.0 - 4.4.3.
0.0.0 - 4.4.35.0.0 - 5.0.3
Medium
CVE-2022-37333
exceedone/exment is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 5.0.0 - 5.0.3 and 0.0.0 - 4.4.3.
0.0.0 - 4.4.35.0.0 - 5.0.3
High

Package versions

Maintainers

Exceed One Co.,Ltd.
Hiroshi Sato

Direct Dependencies

DependencyLast ReleaseScore
laravel/ui
Version ^4.2
—
—
lcobucci/jwt
Version ^5.0
—
—
mews/purifier
Version ^3.2
—
—
laravel/helpers
Version ^1.6
—
—
exment-git/spout
Version ^4.0
—
—

Weekly Downloads

Info

Last Published
8 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform