Clear documentation and an active project structure add confidence. Pin the GitHub Actions dependencies and address the high-confidence workflow warning before relying on automated releases.
72%
Total Score
100
100
100
75
A post-create-project-cmd script runs during installation, creating some supply-chain exposure, although this is a single documented Composer lifecycle hook rather than evidence of abandonment.
All six workflows were analyzed without audit gaps, and permissions are not broadly writable, but all 13 action references are unpinned. A high-confidence template-injection finding and a high-confidence archived action add meaningful release-workflow hygiene risk; the pull_request_target trigger had no reported untrusted checkout or script-injection sink.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-58657 getgrav/grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0-rc.9 - 2.0.0-rc.9. | 2.0.0-rc.9 - 2.0.0-rc.9 | Medium |
CVE-2026-61453 getgrav/grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 2.0.0. | 2.0.0 - 2.0.0 | Medium |
CVE-2026-61449 getgrav/grav is vulnerable to Security Vulnerability in versions 2.0.1 - 2.0.1. | 2.0.1 - 2.0.1 | Medium |
CVE-2026-65608 getgrav/grav is vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in versions 1.7.0 - 2.0.9. | 1.7.0 - 2.0.9 | High |
CVE-2026-69088 getgrav/grav is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 2.0.7 - 2.0.10. | 2.0.7 - 2.0.10 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
twig/twig Version 3.x-dev | — | — |
filp/whoops Version ~2.16 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/yaml Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.