Its large dependency surface adds integration and maintenance overhead. Repository automation also has high-confidence workflow findings and only covered 30 of 56 workflows, despite strong ongoing development and security tooling.
78%
Total Score
100
50
100
75
The package declares 131 runtime dependencies and 35 development dependencies. That breadth is expected for an e-commerce platform but increases upgrade, compatibility, and transitive supply-chain overhead.
The package runs post-install and post-update Composer scripts. These are common for a framework-sized application, but they add installation-time execution and should be understood when deploying the dependency.
The audit found high-confidence template-injection, artipacked, unpinned-image, and overprovisioned-secret findings, including in release workflows; top-level write permissions also appear in 10 workflows. The audit covered only 30 of 56 workflows, so this is a meaningful supply-chain hygiene concern rather than a clean bill of health.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-48016 shopware/platform is vulnerable to Authentication Bypass by Spoofing in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18. | 0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1 | Medium |
CVE-2026-48014 shopware/platform is vulnerable to Missing Authorization in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18. | 0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1 | Medium |
CVE-2026-48011 shopware/platform is vulnerable to Observable Timing Discrepancy in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18. | 0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1 | Low |
CVE-2026-48010 shopware/platform is vulnerable to Improper Privilege Management in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18. | 0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1 | Medium |
CVE-2026-48009 shopware/platform is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18. | 0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version ^0.8.1 | — | — |
psr/log Version ^3.0.0 | — | — |
psr/cache Version ^3.0.0 | — | — |
psr/clock Version ^1.0.0 | — | — |
twig/twig Version ^3.29.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.