It includes tests, clear licensing, release notes, and a security policy. GitHub Actions use all 16 actions without pinned references, a manageable supply-chain hygiene weakness.
88%
Total Score
100
100
75
A post-autoload-dump install-time script is present. This adds some installation complexity, but the provided signals do not show unsafe behavior or an excessive script set.
All 6 workflows were analyzed with no untrusted checkouts, injection findings, or audit findings, and permissions are not broadly writable. However, all 16 action references are unpinned, leaving a moderate reproducibility and action-substitution weakness.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-24980 kitodo/presentation is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 2.3.2, 3.0.0 - 3.2.3 and 3.3.0 - 3.3.4. | 0.0.0 - 2.3.23.0.0 - 3.2.33.3.0 - 3.3.4 | High |
CVE-2020-16095 kitodo/presentation is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.1.2. | 0.0.0 - 3.1.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4|^13.4 | — | — |
symfony/process Version ^7.4 | — | — |
solarium/solarium Version ^6.4 | — | — |
typo3/cms-extbase Version ^12.4|^13.4 | — | — |
typo3/cms-install Version ^12.4|^13.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.