mautic/core 7.2.0 presents a strong dependency-health profile: it has a long release history, frequent recent releases, a stable major version, active non-archived organization-backed development, substantial recent commit and pull-request activity, and a broad contributor base. Licensing, tests, repository tooling, security policy, and workflow analysis are also reassuring. The main caveats are install-time lifecycle scripts, several workflows without top-level token permissions, and the linked repository not explicitly naming this package; the latter may be explained by the package being part of a monorepo, but it reduces provenance clarity. Overall, the available evidence supports adoption, with normal supply-chain review of Composer scripts and package provenance still advisable.
91%
Total Score
100
100
94
80
post-install-cmd and post-update-cmd scripts introduce install-time execution and therefore deserve review, although lifecycle hooks are not by themselves evidence of poor maintenance.
The repository name does not match mautic/core and its README does not mention the package, which weakens direct package-to-repository provenance; this may be expected for a monorepo but remains a transparency caution.
Nine workflows declare read-only permissions, but four lack top-level permissions and two declare top-level write access, leaving some workflow permission hardening gaps.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-9811 mautic/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.1.2. | 7.0.0 - 7.1.2 | Medium |
CVE-2026-9809 mautic/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.1.2. | 7.0.0 - 7.1.2 | High |
CVE-2026-9808 mautic/core is vulnerable to Incorrect Authorization in versions 7.0.0 - 7.1.2. | 7.0.0 - 7.1.2 | High |
CVE-2026-9559 mautic/core is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 7.0.0 - 7.1.2. | 7.0.0 - 7.1.2 | Critical |
CVE-2026-9557 mautic/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 4.0.0 - 4.4.13, 5.0.0 - 5.2.11, 6.0.0 - 6.0.9 and 7.0.0 - 7.1.2. | 4.0.0 - 4.4.135.0.0 - 5.2.116.0.0 - 6.0.9 +1 more | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mautic/core-lib Version ^7.0 | — | — |
composer/installers Version ^2.3 | — | — |
cweagans/composer-patches Version ^1.7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.