Clear documentation, release notes, repository tests, and a security policy support adoption. The main weakness is that all seven workflow action references are unpinned, which reduces build reproducibility.
87%
Total Score
100
94
83
The project uses Make and Composer build tooling, but no security-scanning tools were detected; the repository's security policy provides some transparency but does not replace scanning.
All three workflows were analyzed with no untrusted checkouts, script injection, or audit findings, and permissions are scoped in some workflows. However, all 7 action references are unpinned, leaving a reproducibility and mutable-build concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-41749 nystudio107/craft-seomatic is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.4.11. | 0.0.0 - 3.4.11 | Critical |
CVE-2021-41750 nystudio107/craft-seomatic is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.11. | 0.0.0 - 3.4.11 | Medium |
CVE-2020-12790 nystudio107/craft-seomatic is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 3.2.49. | 0.0.0 - 3.2.49 | High |
CVE-2020-9757 nystudio107/craft-seomatic is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 3.3.0. | 0.0.0 - 3.3.0 | Critical |
CVE-2018-14716 nystudio107/craft-seomatic is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.1.4. | 0.0.0 - 3.1.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
php-science/textrank Version ^1.0.3 | — | — |
davechild/textstatistics Version ^1.0.3 | — | — |
nystudio107/craft-code-editor Version ^1.0.14 | — | — |
nystudio107/craft-plugin-vite Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.