Package Health

craftcms/aws-s3

Amazon S3 integration for Craft CMS

Latest 2.3.2PackagistPackagist

80%

Total Score

healthy

Healthy overall; regular releases and organization backing outweigh thin recent activity and unpinned workflow actions.

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

Only 2 commits from 1 active maintainer occurred in the last 3 months, indicating limited recent development, though the release history shows ongoing publishing.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.

Workflow auditcaution

All three workflows were analyzed with no dangerous triggers, injection findings, or other audit findings. However, all 3 of 3 action references are unpinned, which weakens build reproducibility.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-32265
craftcms/aws-s3 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 2.0.2 - 2.2.4.
2.0.2 - 2.2.4
Medium
AIKIDO-2026-10273
craftcms/aws-s3 is vulnerable to Information Disclosure in versions 1.0.0 - 2.2.4.
1.0.0 - 2.2.4
Low

Package versions

Maintainers

Pixel & Tonic

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^4.0.0-beta.1|^5.0.0-beta.1
—
—
craftcms/flysystem
Version ^1.0.0-beta.2|^2.0.0
—
—
league/flysystem-aws-s3-v3
Version ^3.0.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform