Package Health

getkirby/cms

The project is actively maintained, organization-backed, well documented, and supported by testing and security tooling. Workflow auditing also found high-confidence template-injection and secret-inheritance issues, so this preview needs careful isolation and review.

Latest 6.0.0-alpha.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The artifact contains license files, but the manifest declares the package proprietary while detected license text is MIT-0. That mismatch creates a real legal and transparency concern despite the presence of licensing material.

Version stabilitycaution

This release is an alpha preview while the package has an established stable major and only 5% recent prereleases. The release notes explicitly say not to use Kirby 6 in production yet.

Workflow auditcaution

All four workflows were analyzed and use pinned actions, with no untrusted checkout or script-injection trigger detected. However, high-confidence template-injection findings and secrets-inherit findings remain, while the floating latest container image adds workflow hygiene risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-75592
getkirby/cms is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.9.5 and 5.0.0 - 5.5.2.
0.0.0 - 4.9.55.0.0 - 5.5.2
Medium
CVE-2026-71415
getkirby/cms is vulnerable to Missing Authorization in versions 5.0.0 - 5.5.2.
5.0.0 - 5.5.2
High
CVE-2026-75594
getkirby/cms is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 4.9.4 and 5.0.0 - 5.5.2.
0.0.0 - 4.9.45.0.0 - 5.5.2
High
CVE-2026-69127
getkirby/cms is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 0.0.0 - 4.9.4 and 5.0.0 - 5.5.2.
0.0.0 - 4.9.45.0.0 - 5.5.2
Medium
CVE-2026-54005
getkirby/cms is vulnerable to Missing Authorization in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3.
0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3
High

Package versions

Maintainers

Kirby Team

Direct Dependencies

DependencyLast ReleaseScore
filp/whoops
Version 2.18.4
symfony/yaml
Version 7.4.14
composer/semver
Version 3.4.4
erusev/parsedown
Version 1.8.0
phpmailer/phpmailer
Version 7.1.1

Weekly Downloads

Info

Last Published
2 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform