Calendar bundle for OroPlatform-based applications.See https://doc.oroinc.com/user/back-office/activities/calendar-events/ for more information.
80%
Total Score
100
100
83
75
The repository name does not match the package name and its README does not mention the package, creating a genuine concern that the linked source may not clearly identify this release.
The repository has only 9 stars and 9 forks, indicating limited community visibility; this is supporting evidence rather than a maintenance verdict.
Composer build tooling is present, but no security-scanning tooling was detected, leaving an avoidable gap in repository security hygiene.
No repository security policy was found, leaving vulnerability-reporting expectations less transparent for a substantial application bundle.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-32062 oro/calendar-bundle is vulnerable to Improper Access Control in versions 4.2.0 - 4.2.6, 5.0.0 - 5.0.6 and 5.1.0 - 5.1.1. | 4.2.0 - 4.2.65.0.0 - 5.0.65.1.0 - 5.1.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
oro/platform Version 7.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.