Kimai - Time Tracking
78%
Total Score
healthy
Packagist marks this package abandoned, although its repository is active, documented, tested, and maintained by an organization.
Packagist marks the package abandoned and names kimai/kimai as its replacement; this is a real adoption and continuity concern despite strong activity elsewhere.
| Title | Versions | Severity |
|---|---|---|
CVE-2019-15481 kevinpapst/kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.1. | 0.0.0 - 1.1 | Medium |
CVE-2021-43515 kevinpapst/kimai2 is vulnerable to Improper Neutralization of Formula Elements in a CSV File in versions 0.0.0 - 1.14.1. | 0.0.0 - 1.14.1 | High |
CVE-2021-4033 kevinpapst/kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 1.16.7. | 0.0.0 - 1.16.7 | Medium |
CVE-2021-3983 kevinpapst/kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.16.3. | 0.0.0 - 1.16.3 | Medium |
CVE-2021-3985 kevinpapst/kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.16.3. | 0.0.0 - 1.16.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
mpdf/mpdf Version ^8.0 | — | — |
league/csv Version ^9.4 | — | — |
doctrine/orm Version ^2.8 | — | — |
symfony/flex Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.