The project has clear release notes, tests, a security policy, and active maintenance. Most workflow action references are unpinned, which weakens build reproducibility despite a complete audit finding no dangerous workflow behavior.
87%
Total Score
100
100
100
75
Five Composer install and update lifecycle scripts run package-managed setup tasks; this is a supply-chain exposure worth noting, but the available project and workflow evidence shows an established, actively maintained application.
All 11 workflows were analyzed with no reported audit findings, no untrusted checkouts, and no script injection. However, 21 of 23 action references are unpinned, reducing build reproducibility and leaving references more exposed to upstream changes.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-50886 grumpydictator/firefly-iii is vulnerable to Improper Access Control in versions 0.0.0 - 6.5.9. | 0.0.0 - 6.5.9 | Critical |
CVE-2024-37893 grumpydictator/firefly-iii is vulnerable to Improper Authentication in versions 0.0.0 - 6.1.17. | 0.0.0 - 6.1.17 | Medium |
CVE-2024-22075 grumpydictator/firefly-iii is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 6.1.1. | 0.0.0 - 6.1.1 | Medium |
CVE-2023-1788 grumpydictator/firefly-iii is vulnerable to Insufficient Session Expiration in versions 0.0.0 - 6.0.0. | 0.0.0 - 6.0.0 | Medium |
CVE-2023-1789 grumpydictator/firefly-iii is vulnerable to Improper Input Validation in versions 0.0.0 - 6.0.0. | 0.0.0 - 6.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version <4 | — | — |
laravel/ui Version ^4.2 | — | — |
league/csv Version ^9.10 | — | — |
ramsey/uuid Version ^4.7 | — | — |
jc5/recovery Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.