Package Health

yourls/yourls

The project has a long release history, current activity, clear licensing, and documented security reporting. Its release notes, repository tests, and organization backing provide useful maintenance context.

Latest 1.10.6PackagistPackagist

74%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The release declares 16 runtime dependencies, including platform extensions and several libraries; this is a meaningful dependency surface but not excessive for a full URL-shortening application.

Lifecycle scriptscaution

A post-update-cmd lifecycle script runs during dependency updates, adding some execution-path complexity, although this signal alone does not show harmful behavior.

Workflow auditcaution

All five workflows were analyzed, but all 15 action references are unpinned; the audit also found high-confidence unpinned container images and blanket app-token permissions. A pull_request_target trigger is present without an untrusted checkout or script-injection sink, so these are serious workflow-hygiene cautions rather than a standalone health verdict.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-63135
yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.5.1 - 1.10.3.
1.5.1 - 1.10.3
High
CVE-2020-27388
yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.5 - 1.8.
1.5 - 1.8
Medium
CVE-2022-0088
yourls/yourls is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 1.8.2.
0.0.0 - 1.8.2
Low
CVE-2021-3785
yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.2.
0.0.0 - 1.8.2
Medium
CVE-2021-3783
yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.2.
0.0.0 - 1.8.2
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
aura/sql
Version ^6.0
pomo/pomo
Version ^1.4
geoip2/geoip2
Version ^2.10
rmccue/requests
Version ^2.0
ozh/bookmarkletgen
Version ^1.2

Weekly Downloads

Info

Last Published
23 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform