Storefront for Shopware
91%
Total Score
healthy
Frequent releases, active organization-backed development, and broad contributor participation support a healthy release.
The repository uses Composer, but no security-scanning tools were detected. The missing scanner is a modest transparency gap, not a severe supply-chain concern on its own.
No repository security policy was found. That weakens vulnerability-reporting transparency, although active organization-backed development and recent commits provide compensating maintenance evidence.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10691 shopware/storefront is vulnerable to Cross-site Scripting (XSS) in versions 6.7.0.0 - 6.7.2.0. | 6.7.0.0 - 6.7.2.0 | High |
CVE-2024-27917 shopware/storefront is vulnerable to Use of Cache Containing Sensitive Information in versions 6.5.8.0 - 6.5.8.7. | 6.5.8.0 - 6.5.8.7 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version ^0.8.1 | — | — |
psr/log Version ^3.0.0 | — | — |
psr/clock Version ^1.0.0 | — | — |
twig/twig Version ^3.29.0 | — | — |
symfony/mime Version ~7.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.