Documentation, tests, and release notes support a well-run project. The organization has a broad active contributor base and security processes, while workflow references are not pinned and need tightening.
87%
Total Score
100
100
100
83
All 13 workflows were analyzed successfully, with no untrusted checkouts or script injection; however, all 21 action references are unpinned and two workflows grant top-level write permissions. The only audit finding is low-confidence cache-poisoning, so it is hygiene rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-0955 pimcore/data-hub is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.2.4. | 0.0.0 - 1.2.4 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72 || ^3.8.4 | — | — |
pimcore/pimcore Version ^2026.1 | — | — |
webonyx/graphql-php Version ^15.2.3 | — | — |
pimcore/studio-ui-bundle Version ^2026.2.5 | — | — |
pimcore/studio-backend-bundle Version ^2026.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.