It is licensed, documented, tested, and has no install-time scripts. The workflow audit found no dangerous findings, though three of four actions are unpinned.
88%
Total Score
100
89
83
The repository name does not match the package name and its README does not mention this package. Although a monorepo mismatch can be ordinary, the absence of both links weakens package-to-source traceability.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency gap, not evidence of abandonment by itself.
All one workflow was analyzed successfully, with no untrusted checkouts, script injection, or audit findings, and permissions scoped at job level. However, 3 of 4 action references are unpinned, leaving a supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-54265 magento/community-edition is vulnerable to Incorrect Authorization in versions 2.4.9-alpha1 - 2.4.9-alpha3, 2.4.8-beta1 - 2.4.8-p3, 2.4.7-beta1 - 2.4.7-p8, 0.0.0 - 2.4.6-p13, 2.4.8 - 2.4.8, 2.4.7 - 2.4.7 and 2.4.6 - 2.4.6. | 0.0.0 - 2.4.9-alpha3 | Medium |
CVE-2025-54263 magento/community-edition is vulnerable to Incorrect Authorization in versions 2.4.9-alpha1 - 2.4.9-alpha3, 2.4.8-beta1 - 2.4.8-p3, 2.4.7-beta1 - 2.4.7-p8, 0.0.0 - 2.4.6-p13, 2.4.8 - 2.4.8, 2.4.7 - 2.4.7 and 2.4.6 - 2.4.6. | 0.0.0 - 2.4.9-alpha3 | High |
CVE-2025-54236 magento/community-edition is vulnerable to Improper Input Validation in versions 0.0.0 - 2.4.5-p14, 2.4.6 - 2.4.6, 2.4.6-p1 - 2.4.6-p12, 2.4.5 - 2.4.5, 2.4.9-alpha1 - 2.4.9-alpha2, 2.4.7 - 2.4.7, 2.4.8 - 2.4.8, 2.4.7-beta1 - 2.4.7-p7, 2.4.8-beta1 - 2.4.8-p2 and 2.4.9 - 2.4.9. | 0.0.0 - 2.4.9 | Critical |
CVE-2025-49557 magento/community-edition is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.4.4-p15, 2.4.5-p1 - 2.4.5-p14, 2.4.6-p1 - 2.4.6-p12, 2.4.7-p1 - 2.4.7-p7 and 2.4.8 - 2.4.8. | 0.0.0 - 2.4.8 | High |
CVE-2025-47110 magento/community-edition is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.4.8-beta1 - 2.4.8-p1, 2.4.7-beta1 - 2.4.7-p6, 0.0.0 - 2.4.5-p13, 2.4.7 - 2.4.7, 2.4.8 - 2.4.8, 2.4.5 - 2.4.5, 2.4.6-p1 - 2.4.6-p11 and 2.4.6 - 2.4.6. | 0.0.0 - 2.4.8 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2 || ^3 | — | — |
ramsey/uuid Version ^4.2 | — | — |
php-db/phpdb Version ^0.4 | — | — |
symfony/intl Version ^7.4 | — | — |
symfony/mime Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.