Package Health

juzaweb/cms

The project includes tests, a README, release notes, and a matching source repository. The declared MIT license conflicts with the detected GPL-2.0 license, while the repository recorded no commits in the last three months and has no security policy. Composer install and update scripts also deserve review before deployment.

Latest 5.0.5PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The manifest declares MIT, but the artifact and repository license file are detected as GPL-2.0. Because the declared and detected licenses differ, licensing terms should be resolved before adoption.

Lifecycle scriptscaution

The package runs post-autoload-dump, post-create-project-cmd, post-root-package-install, and post-update-cmd scripts. These are plausible for a Composer application scaffold, but they execute during installation or updates and increase dependency-installation exposure.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers during the last three months. Recent releases and a non-archived repository provide some counterweight, but the current maintenance pause raises abandonment risk.

Security policycaution

The linked repository has no security policy. This reduces transparency for reporting and handling vulnerabilities in a CMS with substantial runtime functionality.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-6735
juzaweb/cms is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.4.2.
0.0.0 - 3.4.2
Medium
CVE-2025-6736
juzaweb/cms is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.4.2.
0.0.0 - 3.4.2
Medium
CVE-2025-5420
juzaweb/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.2.
0.0.0 - 3.4.2
Low
CVE-2023-46906
juzaweb/cms is vulnerable to Incorrect Authorization in versions 0.0.0 - 3.4.
0.0.0 - 3.4
Medium
CVE-2023-46468
juzaweb/cms is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 3.4.
0.0.0 - 3.4
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
juzaweb/api
Version ^1.0
—
—
juzaweb/blog
Version ^1.0
—
—
juzaweb/core
Version ^5.0
—
—
juzaweb/admin
Version @dev
—
—
symfony/cache
Version ^6.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform