Package Health

shopware/storefront

Storefront for Shopware

Latest v6.7.15.1PackagistPackagist

91%

Total Score

healthy

Frequent releases, active organization-backed development, and broad contributor participation support a healthy release.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The repository uses Composer, but no security-scanning tools were detected. The missing scanner is a modest transparency gap, not a severe supply-chain concern on its own.

Security policycaution

No repository security policy was found. That weakens vulnerability-reporting transparency, although active organization-backed development and recent commits provide compensating maintenance evidence.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10691
shopware/storefront is vulnerable to Cross-site Scripting (XSS) in versions 6.7.0.0 - 6.7.2.0.
6.7.0.0 - 6.7.2.0
High
CVE-2024-27917
shopware/storefront is vulnerable to Use of Cache Containing Sensitive Information in versions 6.5.8.0 - 6.5.8.7.
6.5.8.0 - 6.5.8.7
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mcp/sdk
Version ^0.8.1
—
—
psr/log
Version ^3.0.0
—
—
psr/clock
Version ^1.0.0
—
—
twig/twig
Version ^3.29.0
—
—
symfony/mime
Version ~7.4.12
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform