Package Health

mahocommerce/maho

Healthy and reasonable to depend on, with active project backing and strong maintenance evidence. The main caveat is that one contributor made about 85% of recent commits, while several workflows grant write access without narrowly declared permissions.

Latest 26.9.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Dangerous workflowscaution

Two workflows use pull_request_target and one workflow combines workflow-run behavior with an untrusted checkout. No script-injection workflows were detected, but these patterns warrant review because they can expose privileged automation to untrusted code.

Repo bus factorcaution

One contributor made about 85% of the 251 recent commits, creating concentration risk. The six active contributors and organization ownership partly compensate, so this is a genuine but non-severe maintenance concern.

Token permissionscaution

Three of 22 workflows declare top-level write permissions, while 18 lack top-level permissions declarations. The broad or implicit permission configuration reduces least-privilege transparency and adds workflow supply-chain exposure.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-58449
mahocommerce/maho is vulnerable to Reliance on File Name or Extension of Externally-Supplied File in versions 0.0.0 - 25.9.0.
0.0.0 - 25.9.0
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ^5.6
—
—
doctrine/dbal
Version ^4.4
—
—
dompdf/dompdf
Version ^3.1
—
—
symfony/cache
Version ^7.4
—
—
symfony/mailer
Version ^7.4
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform