Package Health

craftcms/commerce

Craft Commerce

Latest 2.0.0-beta.13.1PackagistPackagist

87%

Total Score

healthy

Healthy: active maintenance and organization backing make this release a strong dependency choice.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

Composer build tooling is present, but no repository security scanning tool was detected, leaving a modest verification gap.

Version stabilitycaution

This specific release is a beta while the package now has a stable 5.7.5 release, so the assessed version carries some maturity risk despite a generally stable recent release profile.

Workflow auditcaution

Both workflows were analyzed with no dangerous triggers, untrusted checkouts, injection findings, or audit findings. However, both action references are unpinned, which is a minor reproducibility and supply-chain hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-55795
craftcms/commerce is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 5.0.0 - 5.6.4 and 4.0.0 - 4.11.1.
4.0.0 - 4.11.15.0.0 - 5.6.4
Medium
CVE-2026-32270
craftcms/commerce is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0 - 5.5.4 and 4.0.0 - 4.10.2.
4.0.0 - 4.10.25.0.0 - 5.5.4
Low
CVE-2026-32271
craftcms/commerce is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 4.0.0 - 4.10.2 and 5.0.0 - 5.5.4.
4.0.0 - 4.10.25.0.0 - 5.5.4
High
CVE-2026-32272
craftcms/commerce is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 5.0.0 - 5.6.0.
5.0.0 - 5.6.0
High
AIKIDO-2026-10370
craftcms/commerce is vulnerable to SQL Injection in versions 3.0.0 - 4.10.2 and 5.0.0 - 5.5.4.
3.0.0 - 4.10.25.0.0 - 5.5.4
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^3.0.13
—
—
dompdf/dompdf
Version ~0.8.2
—
—
moneyphp/money
Version ^3.1.3
—
—
dannyvankooten/vat.php
Version ^1.1.2
—
—
phpoffice/phpspreadsheet
Version ^1.4
—
—

Weekly Downloads

Info

Last Published
7 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform