Package Health

mautic/core

mautic/core 7.2.0 presents a strong dependency-health profile: it has a long release history, frequent recent releases, a stable major version, active non-archived organization-backed development, substantial recent commit and pull-request activity, and a broad contributor base. Licensing, tests, repository tooling, security policy, and workflow analysis are also reassuring. The main caveats are install-time lifecycle scripts, several workflows without top-level token permissions, and the linked repository not explicitly naming this package; the latter may be explained by the package being part of a monorepo, but it reduces provenance clarity. Overall, the available evidence supports adoption, with normal supply-chain review of Composer scripts and package provenance still advisable.

Latest 7.2.0PackagistPackagist

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

post-install-cmd and post-update-cmd scripts introduce install-time execution and therefore deserve review, although lifecycle hooks are not by themselves evidence of poor maintenance.

Repo package mentioncaution

The repository name does not match mautic/core and its README does not mention the package, which weakens direct package-to-repository provenance; this may be expected for a monorepo but remains a transparency caution.

Token permissionscaution

Nine workflows declare read-only permissions, but four lack top-level permissions and two declare top-level write access, leaving some workflow permission hardening gaps.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-9811
mautic/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.1.2.
7.0.0 - 7.1.2
Medium
CVE-2026-9809
mautic/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.1.2.
7.0.0 - 7.1.2
High
CVE-2026-9808
mautic/core is vulnerable to Incorrect Authorization in versions 7.0.0 - 7.1.2.
7.0.0 - 7.1.2
High
CVE-2026-9559
mautic/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 7.0.0 - 7.1.2.
7.0.0 - 7.1.2
Critical
CVE-2026-9557
mautic/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 4.0.0 - 4.4.13, 5.0.0 - 5.2.11, 6.0.0 - 6.0.9 and 7.0.0 - 7.1.2.
4.0.0 - 4.4.135.0.0 - 5.2.116.0.0 - 6.0.9 +1 more
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mautic/core-lib
Version ^7.0
composer/installers
Version ^2.3
cweagans/composer-patches
Version ^1.7.3

Weekly Downloads

Info

Last Published
18 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform