Package Health

kevinpapst/kimai2

Kimai - Time Tracking

Latest 2.69.0PackagistPackagist

78%

Total Score

healthy

Packagist marks this package abandoned, although its repository is active, documented, tested, and maintained by an organization.

Are you affected? Scan for Free

Health Score Breakdown

Registry deprecationcaution

Packagist marks the package abandoned and names kimai/kimai as its replacement; this is a real adoption and continuity concern despite strong activity elsewhere.

Vulnerabilities

TitleVersionsSeverity
CVE-2019-15481
kevinpapst/kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.1.
0.0.0 - 1.1
Medium
CVE-2021-43515
kevinpapst/kimai2 is vulnerable to Improper Neutralization of Formula Elements in a CSV File in versions 0.0.0 - 1.14.1.
0.0.0 - 1.14.1
High
CVE-2021-4033
kevinpapst/kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 1.16.7.
0.0.0 - 1.16.7
Medium
CVE-2021-3983
kevinpapst/kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.16.3.
0.0.0 - 1.16.3
Medium
CVE-2021-3985
kevinpapst/kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.16.3.
0.0.0 - 1.16.3
High

Package versions

Maintainers

Kevin Papst
All contributors

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
mpdf/mpdf
Version ^8.0
—
—
league/csv
Version ^9.4
—
—
doctrine/orm
Version ^2.8
—
—
symfony/flex
Version ^2
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform