Recent commits from three contributors, security scanning, and a security policy provide useful maintenance evidence. The package is clearly documented and licensed, but its stated Pimcore Studio migration gap limits its future value.
62%
Total Score
88
100
94
83
There is one new pull request in the last month and four open issues, showing some ongoing interaction but limited recent issue resolution.
The repository name does not exactly match the package name and its README does not mention the full package identifier, so package-to-repository identity is less explicit; the close naming relationship partly mitigates this.
All seven workflows were analyzed with no findings and no untrusted checkout or script-injection sinks. However, all nine action references are unpinned and one workflow grants top-level write access, creating a modest reproducibility and permissions concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-23496 pimcore/web2print-tools-bundle is vulnerable to Improper Access Control in versions 6.0.0-RC1 - 6.1 and 0.0.0 - 5.2.1. | 0.0.0 - 5.2.16.0.0-RC1 - 6.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pimcore/pimcore Version ^12.3 | — | — |
pimcore/admin-ui-classic-bundle Version ^2.0 | — | — |
pimcore/output-data-config-toolkit-bundle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.