Package Health

pterodactyl/panel

The MIT license, full source tree, tests, changelog, and security policy make the project easy to inspect. Organization backing and seven active contributors provide useful continuity.

Latest v0.6.0-beta.2.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

The package runs pre- and post-install/update Composer scripts. These are operationally relevant for a Laravel application and add some install-time complexity, but are not unusual for this package type.

Repo toolingcaution

Composer build tooling is present. No security scanning tools were detected, leaving a modest security-process gap for a substantial application.

Workflow auditcaution

All four workflows were analyzed and scope permissions at job level, with no untrusted checkout or script-injection trigger findings. However, the release workflow has a high-confidence template-injection finding, and 13 of 14 action references are unpinned; the low-confidence cache finding is only a hygiene concern.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-54593
pterodactyl/panel is vulnerable to Improper Restriction of Security Token Assignment in versions 0.0.0 - 1.12.3.
0.0.0 - 1.12.3
High
CVE-2026-61609
pterodactyl/panel is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.7.0 - 1.12.4.
1.7.0 - 1.12.4
High
CVE-2026-35202
pterodactyl/panel is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 1.12.3.
0.0.0 - 1.12.3
Low
CVE-2026-26016
pterodactyl/panel is vulnerable to Unverified Ownership in versions 0.0.0 - 1.12.1.
0.0.0 - 1.12.1
Critical
CVE-2025-69198
pterodactyl/panel is vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in versions 0.0.0 - 1.12.0.
0.0.0 - 1.12.0
Medium

Package versions

Maintainers

Dane Everitt

Direct Dependencies

DependencyLast ReleaseScore
lord/laroute
Version 2.4.4
doctrine/dbal
Version 2.5.12
nesbot/carbon
Version 1.22.1
predis/predis
Version 1.1.1
laravel/tinker
Version 1.0.0

Weekly Downloads

Info

Last Published
9 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform