Its repository is not archived, and the package has a long release history. Clear documentation, tests, and licensing provide useful support, but no security policy is present.
68%
Total Score
67
100
94
83
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The release published during that period partly offsets this, but the source-level maintenance signal is weak.
There were no new or closed issues or pull requests in the last month, and 20 issues remain open; this indicates limited current project interaction.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all 6 action references are unpinned, weakening build reproducibility and supply-chain protection.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-5237 oneup/uploader-bundle is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 2.0.0 - 2.1.5 and 1.0.0 - 1.9.3. | 1.0.0 - 1.9.32.0.0 - 2.1.5 | High |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.4 || ^3.0 | — | — |
symfony/mime Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/yaml Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/asset Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/finder Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.