Pimcore Ecommerce Bundle
15%
Total Score
100
69
83
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk even though this specific release is stable.
The linked source repository is archived. An archived repository is a severe abandonment risk because ordinary maintenance and issue handling are no longer expected.
The package has 31 releases over roughly 3 years and a median release interval of about 23 days, but only one release appeared in the last 12 months. This supports historical maturity while indicating sharply reduced recent activity.
All eight workflows were analyzed, but all 14 action references are unpinned, and one pull_request_target workflow checks out untrusted content; these create meaningful workflow supply-chain hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-21665 pimcore/ecommerce-framework-bundle is vulnerable to Improper Access Control in versions 0.0.0 - 1.0.10. | 0.0.0 - 1.0.10 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^6.2 | — | — |
pimcore/pimcore Version ^11.0.7 | — | — |
knplabs/knp-paginator-bundle Version ^6.0.0 | — | — |
symfony/webpack-encore-bundle Version ^1.17 || ^2.0 | — | — |
pimcore/personalization-bundle Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.