An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
58%
Total Score
67
100
78
90
There have been three releases since August 2024, but none in roughly the last 19 months, indicating that maintenance may have stopped.
The repository had zero commits and zero active maintainers in the last three months, reinforcing concern that fixes may not be forthcoming.
There are no open issues or pull requests, but there has also been no issue or pull-request activity in the last month, so this is weak maintenance evidence rather than strong validation.
The repository has one star, zero forks, and one watcher, showing very limited visible adoption and review for a security-sensitive extension.
Composer is used for the build, but no security-scanning tool is configured; that is a meaningful hygiene gap for a package intended to address a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/magento2-base Version ~2.3.0 || ~2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.