Healthy and reasonable to depend on, with active project backing and strong maintenance evidence. The main caveat is that one contributor made about 85% of recent commits, while several workflows grant write access without narrowly declared permissions.
86%
Total Score
88
100
80
Two workflows use pull_request_target and one workflow combines workflow-run behavior with an untrusted checkout. No script-injection workflows were detected, but these patterns warrant review because they can expose privileged automation to untrusted code.
One contributor made about 85% of the 251 recent commits, creating concentration risk. The six active contributors and organization ownership partly compensate, so this is a genuine but non-severe maintenance concern.
Three of 22 workflows declare top-level write permissions, while 18 lack top-level permissions declarations. The broad or implicit permission configuration reduces least-privilege transparency and adds workflow supply-chain exposure.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-58449 mahocommerce/maho is vulnerable to Reliance on File Name or Extension of Externally-Supplied File in versions 0.0.0 - 25.9.0. | 0.0.0 - 25.9.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^5.6 | — | — |
doctrine/dbal Version ^4.4 | — | — |
dompdf/dompdf Version ^3.1 | — | — |
symfony/cache Version ^7.4 | — | — |
symfony/mailer Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.