Package Health

grumpydictator/firefly-iii

The project has clear release notes, tests, a security policy, and active maintenance. Most workflow action references are unpinned, which weakens build reproducibility despite a complete audit finding no dangerous workflow behavior.

Latest v6.7.3PackagistPackagist

87%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

Five Composer install and update lifecycle scripts run package-managed setup tasks; this is a supply-chain exposure worth noting, but the available project and workflow evidence shows an established, actively maintained application.

Workflow auditcaution

All 11 workflows were analyzed with no reported audit findings, no untrusted checkouts, and no script injection. However, 21 of 23 action references are unpinned, reducing build reproducibility and leaving references more exposed to upstream changes.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-50886
grumpydictator/firefly-iii is vulnerable to Improper Access Control in versions 0.0.0 - 6.5.9.
0.0.0 - 6.5.9
Critical
CVE-2024-37893
grumpydictator/firefly-iii is vulnerable to Improper Authentication in versions 0.0.0 - 6.1.17.
0.0.0 - 6.1.17
Medium
CVE-2024-22075
grumpydictator/firefly-iii is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 6.1.1.
0.0.0 - 6.1.1
Medium
CVE-2023-1788
grumpydictator/firefly-iii is vulnerable to Insufficient Session Expiration in versions 0.0.0 - 6.0.0.
0.0.0 - 6.0.0
Medium
CVE-2023-1789
grumpydictator/firefly-iii is vulnerable to Improper Input Validation in versions 0.0.0 - 6.0.0.
0.0.0 - 6.0.0
Medium

Package versions

Maintainers

James Cole

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version <4
—
—
laravel/ui
Version ^4.2
—
—
league/csv
Version ^9.10
—
—
ramsey/uuid
Version ^4.7
—
—
jc5/recovery
Version ^2
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform