10%
Total Score
critical
Unfit to use: the package is deprecated and its source repository is archived.
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe dependency and maintenance risk beyond a single withdrawn release.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that is no longer actively maintained.
The linked source repository is archived, making continued fixes and maintenance unlikely even though it was pushed recently.
The package has 169 releases over roughly nine years, but it has had no registry releases in the last 12 months, indicating a stalled release cadence.
There were no new or closed issues and no merged pull requests in the last month, with only one open pull request, showing little current development activity.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-11956 pimcore/customer-management-framework-bundle is vulnerable to SQL Injection: Hibernate in versions 0.0.0 - 4.2.1. | 0.0.0 - 4.2.1 | High |
CVE-2024-21667 pimcore/customer-management-framework-bundle is vulnerable to Improper Access Control in versions 0.0.0 - 4.0.6. | 0.0.0 - 4.0.6 | Medium |
CVE-2024-21666 pimcore/customer-management-framework-bundle is vulnerable to Improper Access Control in versions 0.0.0 - 4.0.6. | 0.0.0 - 4.0.6 | Medium |
CVE-2023-4145 pimcore/customer-management-framework-bundle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.2. | 0.0.0 - 3.4.2 | Medium |
CVE-2023-3574 pimcore/customer-management-framework-bundle is vulnerable to Improper Authorization in versions 0.0.0 - 3.4.1. | 0.0.0 - 3.4.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.4.2 | — | — |
symfony/asset Version ^6.2 | — | — |
symfony/config Version ^6.2 | — | — |
pimcore/pimcore Version ^11.2 | — | — |
symfony/console Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.