Healthy and suitable to use, with some maintenance caveats. The package is backed by an active organization, has tests, release notes, and recent repository activity, but its registry release cadence is slow and the repository lacks a security policy.
78%
Total Score
100
100
94
75
The package has existed since February 2017 with eight releases, but it has had no registry release in the last 12 months and the latest release was about 20 months ago. Recent repository activity partly offsets this, but the registry cadence remains slow.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented despite the module's security-sensitive release notes.
None of the three workflows declares top-level token permissions, which reduces transparency about the permissions granted to automation even though no workflow requests explicit top-level write access.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-24027 prestashop/ps_contactinfo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.3.2. | 0.0.0 - 3.3.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.