The project has a clear README, a security policy, and an organization-backed repository that is still active. The Packagist release is roughly 12 years old, its license files do not align cleanly, and the workflows use unpinned actions with high-confidence template-injection findings.
65%
Total Score
100
80
100
The manifest declares GPL-3.0+ and LGPL-3.0+, while the detected artifact license is BSD-3-Clause; a repository license also exists, but the mismatch should be resolved before redistribution or integration.
The registry shows 17 releases, but the latest was published on 30 June 2014 and there have been no releases in roughly 12 years. This makes the assessed artifact stale even though the linked project is active.
All five analyzed action references are unpinned, and the audit found three high-confidence template-injection findings in the release workflow. No dangerous trigger, untrusted checkout, or broad top-level write permission was reported, so this is a meaningful hygiene concern rather than a standalone severe risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-27516 remdex/livehelperchat is vulnerable to Security Vulnerability in versions 0.0.0 - 4.29. | 0.0.0 - 4.29 | Critical |
CVE-2022-1530 remdex/livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.99. | 0.0.0 - 3.99 | Medium |
CVE-2022-1235 remdex/livehelperchat is vulnerable to Use of Password Hash With Insufficient Computational Effort in versions 0.0.0 - 3.96. | 0.0.0 - 3.96 | High |
CVE-2022-1213 remdex/livehelperchat is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 3.67. | 0.0.0 - 3.67 | High |
CVE-2022-1176 remdex/livehelperchat is vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') in versions 0.0.0 - 3.96. | 0.0.0 - 3.96 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.