Package Health

shopware/platform

Its large dependency surface adds integration and maintenance overhead. Repository automation also has high-confidence workflow findings and only covered 30 of 56 workflows, despite strong ongoing development and security tooling.

Latest v6.7.15.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 131 runtime dependencies and 35 development dependencies. That breadth is expected for an e-commerce platform but increases upgrade, compatibility, and transitive supply-chain overhead.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These are common for a framework-sized application, but they add installation-time execution and should be understood when deploying the dependency.

Workflow auditcaution

The audit found high-confidence template-injection, artipacked, unpinned-image, and overprovisioned-secret findings, including in release workflows; top-level write permissions also appear in 10 workflows. The audit covered only 30 of 56 workflows, so this is a meaningful supply-chain hygiene concern rather than a clean bill of health.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-48016
shopware/platform is vulnerable to Authentication Bypass by Spoofing in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18.
0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1
Medium
CVE-2026-48014
shopware/platform is vulnerable to Missing Authorization in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18.
0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1
Medium
CVE-2026-48011
shopware/platform is vulnerable to Observable Timing Discrepancy in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18.
0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1
Low
CVE-2026-48010
shopware/platform is vulnerable to Improper Privilege Management in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18.
0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1
Medium
CVE-2026-48009
shopware/platform is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 6.7.0.0 - 6.7.10.1 and 0.0.0 - 6.6.10.18.
0.0.0 - 6.6.10.186.7.0.0 - 6.7.10.1
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mcp/sdk
Version ^0.8.1
—
—
psr/log
Version ^3.0.0
—
—
psr/cache
Version ^3.0.0
—
—
psr/clock
Version ^1.0.0
—
—
twig/twig
Version ^3.29.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform