Package Health

typo3fluid/fluid

Documentation and release notes support straightforward adoption. The project has active organizational maintenance, though all three workflow actions are unpinned and no security policy is published.

Latest 5.3.2PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The repository uses Composer build tooling but reports no security-scanning tools. That leaves a modest assurance gap, without outweighing the strong maintenance evidence.

Security policycaution

No security policy was found in the linked repository. This is a transparency and incident-handling gap, but it is moderated by the active, organization-backed project.

Workflow auditcaution

Both workflows were fully analyzed with no injection, untrusted-checkout, or severity findings, and no workflow has top-level write permissions. However, all 3 of 3 action references are unpinned, creating a minor reproducibility and action-integrity hygiene concern.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-26216
typo3fluid/fluid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 2.0.8, 2.1.0 - 2.1.7, 2.2.0 - 2.2.4, 2.3.0 - 2.3.7, 2.4.0 - 2.4.4, 2.5.0 - 2.5.11 and 2.6.0 - 2.6.10.
2.0.0 - 2.0.82.1.0 - 2.1.72.2.0 - 2.2.4 +4 more
High
CVE-2020-15241
typo3fluid/fluid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 2.0.5, 2.1.0 - 2.1.4, 2.2.0 - 2.2.1, 2.3.0 - 2.3.5, 2.4.0 - 2.4.1, 2.5.0 - 2.5.5 and 2.6.0 - 2.6.1.
2.0.0 - 2.0.52.1.0 - 2.1.42.2.0 - 2.2.1 +4 more
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform