Kirby Starterkit
82%
Total Score
healthy
Regular releases and an active organization-owned repository support this starterkit, despite all recent commits coming from one contributor.
All four recent commits came from one contributor, leaving maintenance activity concentrated and creating a real continuity concern despite organization ownership.
Composer is used for the build, but no repository security-scanning tool was detected; this is a modest transparency gap rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-35174 getkirby/starterkit is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.7.0.2. | 0.0.0 - 3.7.0.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
getkirby/cms Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.