Package Health

mongodb/mongodb-extension

MongoDB driver extension

Latest 2.5.3PackagistPackagist

72%

Total Score

caution

Usable with caveats: active MongoDB-backed maintenance is offset by weak GitHub Actions pinning and workflow hygiene.

Are you affected? Scan for Free

Health Score Breakdown

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response expectations less transparent.

Workflow auditcaution

All 42 action references are unpinned, and the audit found high-confidence template-injection and unpinned-image findings plus secrets inheritance; no untrusted checkout or script-injection path was found, so this is a hygiene concern rather than a standalone severe risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-715664 New
mongodb/mongodb-extension is vulnerable to PHP Object Injection in versions 0.0.1 - 1.21.9, 2.0.0 - 2.1.9 and 2.2.0 - 2.5.2.
0.0.1 - 1.21.92.0.0 - 2.1.92.2.0 - 2.5.2
Medium
AIKIDO-2026-561128 New
mongodb/mongodb-extension is vulnerable to Out-of-Bounds Read in versions 1.15.0 - 1.21.7, 2.0.0 - 2.1.8 and 2.2.0 - 2.5.0.
1.15.0 - 1.21.72.0.0 - 2.1.82.2.0 - 2.5.0
Medium
AIKIDO-2026-440922
mongodb/mongodb-extension is vulnerable to Improper Neutralization of Special Elements in Data Query Logic in versions 0.0.1 - 1.21.5 and 2.0.0 - 2.4.0.
0.0.1 - 1.21.52.0.0 - 2.4.0
High
CVE-2025-12119
mongodb/mongodb-extension is vulnerable to Expired Pointer Dereference in versions 0.0.0 - 1.21.2.
0.0.0 - 1.21.2
Medium

Package versions

Maintainers

Andreas Braun
Jeremy Mikola
Jérôme Tamarelle

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
12 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform