It includes a README, tests, release notes, and a clear GPL license. The linked project is organized and identifiable, but maintenance and security coverage are too weak for a dependable CMS dependency.
18%
Total Score
50
67
75
Packagist marks the entire package as abandoned and lists coastercms/coastercms as its replacement. Package-wide deprecation is a severe adoption risk even though this specific release is stable.
The latest release was published in November 2020, with no releases in the last 12 months. That leaves this Laravel CMS release nearly six years old and unlikely to receive current fixes.
The repository recorded zero commits and zero active maintainers in the measured three-month period, consistent with the long gap since the latest release.
There were no new or closed issues or pull requests in the measured month, while 20 issues remain open. This provides no evidence of ongoing issue handling.
The linked repository has no security policy, leaving no documented process for reporting or coordinating vulnerability fixes. The absence compounds the maintenance concerns but is not independently disqualifying.
| Title | Versions | Severity |
|---|---|---|
CVE-2018-17876 web-feet/coastercms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.5.0 - 5.5.0. | 5.5.0 - 5.5.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.5 | — | — |
fideloper/proxy Version ^4.4 | — | — |
coastercms/framework Version ~8.0 | — | — |
fruitcake/laravel-cors Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.