Package Health

s9y/serendipity

The repository has five active contributors, security reporting guidance, tests, and release notes. Two unpinned workflow actions are a small reproducibility gap; organization backing and recent commits reduce abandonment concerns.

Latest 2.6.1PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

The sole workflow was fully analyzed with no audit findings or untrusted checkout and script-injection paths. However, both analyzed action references are unpinned, creating a modest reproducibility and workflow supply-chain hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-39971
s9y/serendipity is vulnerable to Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in versions 0.0.0 - 2.6.0.
0.0.0 - 2.6.0
High
CVE-2026-39963
s9y/serendipity is vulnerable to Reliance on Cookies without Validation and Integrity Checking in versions 0.0.0 - 2.6.0.
0.0.0 - 2.6.0
Medium

Package versions

Maintainers

Serendipity Team

Direct Dependencies

DependencyLast ReleaseScore
mf2/mf2
Version ^0.5.0
smarty/smarty
Version ^5.1
katzgrau/klogger
Version ^1.0.0
masterminds/html5
Version ^2.9
php81_bc/strftime
Version ^0.5.0

Weekly Downloads

Info

Last Published
2 months ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform