Package Health

october/backend

The MIT license, clear source match, and small runtime dependency set support adoption. Missing security tooling and policy leave transparency weaker.

Latest v1.1.12PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Release historydanger

The package has 169 releases since 2016, but none in the last 12 months and the latest release was in March 2022. That long silence is a meaningful abandonment concern.

Repo commit activitydanger

The repository had zero commits and zero active maintainers in the last three months, consistent with the last push in March 2022 and increasing abandonment risk.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are present. That is a transparency and maintenance weakness, though not severe enough to make the release unfit alone.

Repository archivedcaution

The repository is not archived, but it was last pushed in March 2022. Its unarchived status provides some continuity evidence without offsetting the prolonged inactivity.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Vulnerabilities

TitleVersionsSeverity
CVE-2021-21265
october/backend is vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax in versions 0.0.0 - 1.1.2.
0.0.0 - 1.1.2
Low
CVE-2020-15248
october/backend is vulnerable to Improper Privilege Management in versions 1.0.319 - 1.0.470.
1.0.319 - 1.0.470
Medium
CVE-2020-15249
october/backend is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.319 - 1.0.469.
1.0.319 - 1.0.469
Low
CVE-2020-11083
october/backend is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.319 - 1.0.466.
1.0.319 - 1.0.466
Low
CVE-2020-4061
october/backend is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.319 - 1.0.467.
1.0.319 - 1.0.467
Low

Package versions

Maintainers

Alexey Bobkov
Samuel Georges

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version ~1.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform