Package Health

modx/revolution

The project has a broad active contributor base and a clear security policy. Its workflow references are not pinned, and the license metadata does not fully match the detected license text.

Latest v3.2.4-plPackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The package declares GPL-2.0+ and includes license files, but the detected artifact license is GPL-2.0, so the declaration and detected text do not fully match.

Lifecycle scriptscaution

Install-time scripts run during project creation and autoload generation. These are relevant execution hooks, but their presence is not by itself evidence of poor maintenance or unsafe dependency health.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and hygiene gap.

Version stabilitycaution

This is a stable-major release, but every recent release is marked prerelease, which adds some release-channel uncertainty for consumers.

Workflow auditcaution

All three workflows were analyzed without high- or medium-severity findings or unsafe untrusted checkouts, but all 9 action references are unpinned, reducing build reproducibility and supply-chain hygiene.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-28010
modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.1.0.
0.0.0 - 3.1.0
Medium
CVE-2017-1000067
modx/revolution is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 2.0.0 - 2.5.6.
2.0.0 - 2.5.6
High
CVE-2017-9071
modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.5.7.
0.0.0 - 2.5.7
Medium
CVE-2017-9070
modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.5.7.
0.0.0 - 2.5.7
Medium
CVE-2017-9068
modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.5.7.
0.0.0 - 2.5.7
Medium

Package versions

Maintainers

Jason Coward
Shaun McCormick
Jan Peca

Direct Dependencies

DependencyLast ReleaseScore
xpdo/xpdo
Version ~3.1.0
pimple/pimple
Version ^3.0
smarty/smarty
Version ^4.0
guzzlehttp/psr7
Version ^2.0
psr/http-client
Version ^1.0

Weekly Downloads

Info

Last Published
26 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform