The package is licensed, documented, tested in the repository, and has a security policy. Organization backing and a recent push help, but the limited recent activity and CI image pinning merit care.
62%
Total Score
75
100
89
100
The package has existed since 2013 with 29 releases, but it has had no registry release in the last 12 months, which weakens evidence of ongoing release maintenance.
One contributor made all commits in the last three months, concentrating recent maintenance in a single person; organization ownership provides some capacity but no active second contributor is shown.
Only one commit was recorded in the last three months, indicating thin recent development activity despite the recent repository push.
Composer build tooling is used, but no security-scanning tool was detected, leaving a modest verification gap.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all 10 action references are unpinned and two high-confidence unpinned-image findings reduce CI reproducibility.
| Title | Versions | Severity |
|---|---|---|
CVE-2015-8566 joomla/session is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 1.3.1. | 0.0.0 - 1.3.1 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/deprecation-contracts Version ^2|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.