Regular releases, tests, a changelog, and active dependency tooling support a mature project. The declared MIT license differs from the detected BSD-3-Clause license, so verify licensing before adoption.
62%
Total Score
50
100
94
75
The repository recorded zero commits and zero active maintainers in the last three months. That indicates a meaningful maintenance concern, despite the recent registry releases and last-pushed timestamp.
The artifact includes license files and the repository has a license file, but the manifest declares MIT while the detected primary artifact license is BSD-3-Clause. That mismatch warrants checking the applicable terms.
The repository has no security policy. For a web-based CMS, this reduces transparency about vulnerability reporting and handling.
No workflows were analyzed and one file failed during the audit, so the result is incomplete rather than a clean workflow assessment. No actionable workflow findings were observed in the available data.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-45964 tribalsystems/zenario is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 9.7.61188. | 0.0.0 - 9.7.61188 | Medium |
CVE-2024-45960 tribalsystems/zenario is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 9.7.61188. | 0.0.0 - 9.7.61188 | Medium |
CVE-2024-34461 tribalsystems/zenario is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 9.5.60437. | 0.0.0 - 9.5.60437 | Critical |
CVE-2024-34460 tribalsystems/zenario is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 9.5.60602. | 0.0.0 - 9.5.60602 | Medium |
CVE-2023-44769 tribalsystems/zenario is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 9.4.59197. | 0.0.0 - 9.4.59197 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^1.0.0 | — | — |
php-amqplib/php-amqplib Version 2.5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.