The project includes tests, a README, release notes, and a matching source repository. The declared MIT license conflicts with the detected GPL-2.0 license, while the repository recorded no commits in the last three months and has no security policy. Composer install and update scripts also deserve review before deployment.
62%
Total Score
75
93
50
The manifest declares MIT, but the artifact and repository license file are detected as GPL-2.0. Because the declared and detected licenses differ, licensing terms should be resolved before adoption.
The package runs post-autoload-dump, post-create-project-cmd, post-root-package-install, and post-update-cmd scripts. These are plausible for a Composer application scaffold, but they execute during installation or updates and increase dependency-installation exposure.
The repository recorded 0 commits and 0 active maintainers during the last three months. Recent releases and a non-archived repository provide some counterweight, but the current maintenance pause raises abandonment risk.
The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities in a CMS with substantial runtime functionality.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-6735 juzaweb/cms is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.4.2. | 0.0.0 - 3.4.2 | Medium |
CVE-2025-6736 juzaweb/cms is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.4.2. | 0.0.0 - 3.4.2 | Medium |
CVE-2025-5420 juzaweb/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.2. | 0.0.0 - 3.4.2 | Low |
CVE-2023-46906 juzaweb/cms is vulnerable to Incorrect Authorization in versions 0.0.0 - 3.4. | 0.0.0 - 3.4 | Medium |
CVE-2023-46468 juzaweb/cms is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 3.4. | 0.0.0 - 3.4 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
juzaweb/api Version ^1.0 | — | — |
juzaweb/blog Version ^1.0 | — | — |
juzaweb/core Version ^5.0 | — | — |
juzaweb/admin Version @dev | — | — |
symfony/cache Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.