The project has a broad active contributor base and a clear security policy. Its workflow references are not pinned, and the license metadata does not fully match the detected license text.
86%
Total Score
100
79
67
The package declares GPL-2.0+ and includes license files, but the detected artifact license is GPL-2.0, so the declaration and detected text do not fully match.
Install-time scripts run during project creation and autoload generation. These are relevant execution hooks, but their presence is not by itself evidence of poor maintenance or unsafe dependency health.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and hygiene gap.
This is a stable-major release, but every recent release is marked prerelease, which adds some release-channel uncertainty for consumers.
All three workflows were analyzed without high- or medium-severity findings or unsafe untrusted checkouts, but all 9 action references are unpinned, reducing build reproducibility and supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-28010 modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.1.0. | 0.0.0 - 3.1.0 | Medium |
CVE-2017-1000067 modx/revolution is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 2.0.0 - 2.5.6. | 2.0.0 - 2.5.6 | High |
CVE-2017-9071 modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.5.7. | 0.0.0 - 2.5.7 | Medium |
CVE-2017-9070 modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.5.7. | 0.0.0 - 2.5.7 | Medium |
CVE-2017-9068 modx/revolution is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.5.7. | 0.0.0 - 2.5.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
xpdo/xpdo Version ~3.1.0 | — | — |
pimple/pimple Version ^3.0 | — | — |
smarty/smarty Version ^4.0 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.