Management for Product, Client, Contracts, Subscription, ...
68%
Total Score
caution
Usable with caveats: recent activity is concentrated in one contributor, despite regular releases and organizational backing.
All 3 recent commits came from one contributor, giving a 100% top-contributor share. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.
Only 3 commits were made in the last 3 months, indicating modest recent development activity despite the current release. The recent release cadence partly offsets this, but does not remove the maintenance concern.
The repository has 60 open issues and 9 open pull requests; in the last month it received 4 issues but closed none, while merging 2 pull requests. This suggests some backlog and limited recent issue resolution.
Composer build tooling is present, but no security-scanning tool was detected. For a large web application, that leaves a meaningful maintenance and vulnerability-management gap.
The repository has no security policy or documented security-reporting path. This reduces transparency for handling vulnerabilities in an application that manages business information.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-38080 exceedone/exment is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.0.3 and 0.0.0 - 4.4.3. | 0.0.0 - 4.4.35.0.0 - 5.0.3 | Medium |
CVE-2022-37333 exceedone/exment is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 5.0.0 - 5.0.3 and 0.0.0 - 4.4.3. | 0.0.0 - 4.4.35.0.0 - 5.0.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^4.2 | — | — |
lcobucci/jwt Version ^5.0 | — | — |
mews/purifier Version ^3.2 | — | — |
laravel/helpers Version ^1.6 | — | — |
exment-git/spout Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.