Kernel used by ezsystems/ezplatform and derivatives. Provides the Content Repository, its APIs, and the application's Symfony framework integration.
22%
Total Score
50
60
67
The package has 76 releases over more than six years, but none in the last 12 months; the long release gap is consistent with the archived repository.
There were zero commits and zero active maintainers during the last 3 months, reinforcing that this release is not receiving active maintenance.
The linked repository is archived, which is a severe maintenance and abandonment risk even though it was reportedly pushed on June 25, 2026.
One of six workflows uses pull_request_target, creating some workflow review risk, but no untrusted checkout or script injection was detected.
All six workflows lack top-level permissions declarations, leaving permissions less explicit than ideal; none declares top-level write access.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-48366 ezsystems/ezplatform-kernel is vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in versions 1.3.0 - 1.3.19. | 1.3.0 - 1.3.19 | Low |
CVE-2022-25336 ezsystems/ezplatform-kernel is vulnerable to Exposure of Resource to Wrong Sphere in versions 1.3.0 - 1.3.12. | 1.3.0 - 1.3.12 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
doctrine/orm Version ^2.7 | — | — |
symfony/mime Version ^5.3.0 | — | — |
symfony/yaml Version ^5.3.0 | — | — |
doctrine/dbal Version ^2.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.