PrestaShop productcomments v9.0.0 appears to be a healthy, actively maintained release. It has a long release history, a current stable major version, no registry deprecation, an unarchived organization-owned repository with a recent push, recent commits from four contributors, and active pull-request activity. The artifact is licensed, includes tests and substantial source structure, uses Composer and Dependabot, and has no install-time lifecycle scripts or detected dangerous workflow patterns. The main concerns are the absence of a security policy and explicit top-level permissions in all three analyzed workflows, plus the absence of a changelog; these are transparency and CI-hygiene gaps but are outweighed by the strong maintenance and project-backing evidence.
88%
Total Score
100
100
100
80
The repository has no security policy, leaving vulnerability-reporting and disclosure guidance undocumented; this is a genuine transparency gap, but not evidence of abandonment.
None of the 3 analyzed workflows declares top-level token permissions. Although no workflow has top-level write permissions, explicit least-privilege configuration would provide stronger CI security hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-250803 New prestashop/productcomments is vulnerable to SQL Injection in versions 6.0.0 - 8.0.0. | 6.0.0 - 8.0.0 | High |
CVE-2022-35933 prestashop/productcomments is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.0.2. | 0.0.0 - 5.0.2 | Medium |
CVE-2020-26248 prestashop/productcomments is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 4.0.0 - 4.2.1. | 4.0.0 - 4.2.1 | High |
CVE-2020-26225 prestashop/productcomments is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.2.0. | 4.0.0 - 4.2.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.