Package Health

magento/community-edition

It is licensed, documented, tested, and has no install-time scripts. The workflow audit found no dangerous findings, though three of four actions are unpinned.

Latest 2.4.9PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package name and its README does not mention this package. Although a monorepo mismatch can be ordinary, the absence of both links weakens package-to-source traceability.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency gap, not evidence of abandonment by itself.

Workflow auditcaution

All one workflow was analyzed successfully, with no untrusted checkouts, script injection, or audit findings, and permissions scoped at job level. However, 3 of 4 action references are unpinned, leaving a supply-chain hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-54265
magento/community-edition is vulnerable to Incorrect Authorization in versions 2.4.9-alpha1 - 2.4.9-alpha3, 2.4.8-beta1 - 2.4.8-p3, 2.4.7-beta1 - 2.4.7-p8, 0.0.0 - 2.4.6-p13, 2.4.8 - 2.4.8, 2.4.7 - 2.4.7 and 2.4.6 - 2.4.6.
0.0.0 - 2.4.9-alpha3
Medium
CVE-2025-54263
magento/community-edition is vulnerable to Incorrect Authorization in versions 2.4.9-alpha1 - 2.4.9-alpha3, 2.4.8-beta1 - 2.4.8-p3, 2.4.7-beta1 - 2.4.7-p8, 0.0.0 - 2.4.6-p13, 2.4.8 - 2.4.8, 2.4.7 - 2.4.7 and 2.4.6 - 2.4.6.
0.0.0 - 2.4.9-alpha3
High
CVE-2025-54236
magento/community-edition is vulnerable to Improper Input Validation in versions 0.0.0 - 2.4.5-p14, 2.4.6 - 2.4.6, 2.4.6-p1 - 2.4.6-p12, 2.4.5 - 2.4.5, 2.4.9-alpha1 - 2.4.9-alpha2, 2.4.7 - 2.4.7, 2.4.8 - 2.4.8, 2.4.7-beta1 - 2.4.7-p7, 2.4.8-beta1 - 2.4.8-p2 and 2.4.9 - 2.4.9.
0.0.0 - 2.4.9
Critical
CVE-2025-49557
magento/community-edition is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.4.4-p15, 2.4.5-p1 - 2.4.5-p14, 2.4.6-p1 - 2.4.6-p12, 2.4.7-p1 - 2.4.7-p7 and 2.4.8 - 2.4.8.
0.0.0 - 2.4.8
High
CVE-2025-47110
magento/community-edition is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.4.8-beta1 - 2.4.8-p1, 2.4.7-beta1 - 2.4.7-p6, 0.0.0 - 2.4.5-p13, 2.4.7 - 2.4.7, 2.4.8 - 2.4.8, 2.4.5 - 2.4.5, 2.4.6-p1 - 2.4.6-p11 and 2.4.6 - 2.4.6.
0.0.0 - 2.4.8
Critical

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2 || ^3
—
—
ramsey/uuid
Version ^4.2
—
—
php-db/phpdb
Version ^0.4
—
—
symfony/intl
Version ^7.4
—
—
symfony/mime
Version ^7.4
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform