The project has seven active contributors, a clear README, and release notes for this version. Workflow hygiene needs attention because all 14 action references are unpinned and one high-confidence template-injection finding was reported; no security policy is published.
79%
Total Score
100
100
94
75
No security policy was found in the repository, leaving vulnerability-reporting expectations and response procedures less transparent.
The assessed release is marked stable and not prerelease, but the reported latest version is 8.5.2 while this release is 13.3.0, creating a registry-data consistency concern.
Both workflows were analyzed successfully, with no untrusted checkout or script-injection counts and no top-level write permissions. However, all 14 action references are unpinned, and a high-confidence template-injection finding plus unpinned actions require workflow hardening.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-802492 in2code/powermail is vulnerable to Server-Side Template Injection (SSTI) in versions 3.4.0 - 8.5.1, 9.0.0 - 10.9.2, 11.0.0 - 12.6.0 and 13.0.0 - 13.2.0. | 3.4.0 - 8.5.19.0.0 - 10.9.211.0.0 - 12.6.0 +1 more | Critical |
CVE-2025-7899 in2code/powermail is vulnerable to Authorization Bypass Through User-Controlled Key in versions 12.0.0 - 12.5.3 and 13.0.0 - 13.0.0. | 12.0.0 - 12.5.313.0.0 - 13.0.0 | Medium |
CVE-2024-47047 in2code/powermail is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 7.5.1, 8.0.0 - 8.5.1, 9.0.0 - 10.9.1 and 12.0.0 - 12.4.1. | 0.0.0 - 7.5.18.0.0 - 8.5.19.0.0 - 10.9.1 +1 more | Medium |
CVE-2024-45233 in2code/powermail is vulnerable to Improper Access Control in versions 0.0.0 - 7.5.0, 8.0.0 - 8.5.0, 9.0.0 - 10.9.0 and 11.0.0 - 12.4.0. | 0.0.0 - 7.5.08.0.0 - 8.5.09.0.0 - 10.9.0 +1 more | Medium |
CVE-2024-45232 in2code/powermail is vulnerable to Authorization Bypass Through User-Controlled Key in versions 11.0.0 - 12.4.0, 9.0.0 - 10.9.0, 8.0.0 - 8.5.0 and 0.0.0 - 7.5.0. | 0.0.0 - 7.5.08.0.0 - 8.5.09.0.0 - 10.9.0 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 | — | — |
symfony/rate-limiter Version ^7.2 | — | — |
phpoffice/phpspreadsheet Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.