Package Health

solspace/craft-freeform

Reliable form builder that's ready for wherever your project takes you.

Latest 4.0.0-beta.15.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

Composer post-install and post-update scripts run during dependency operations. This is a mild supply-chain exposure, but the signal does not show that the scripts are harmful.

Repo toolingcaution

Composer is used for builds, but no security scanning tools were detected. That is a modest transparency gap for a maintained package, not evidence of abandonment.

Version stabilitycaution

This assessed release is beta.15.1 while the latest version is 5.16.0, so it is a prerelease and materially behind the current stable line.

Workflow auditcaution

Both workflows were analyzed successfully, use read-only permissions, and had no auditor findings or untrusted checkout or script-injection sinks. However, all 15 analyzed action references are unpinned, leaving avoidable build-integrity risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-833597 New
solspace/craft-freeform is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.0.0 - 5.16.1.
5.0.0 - 5.16.1
High
AIKIDO-2026-470568 New
solspace/craft-freeform is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 5.0.0 - 5.16.0.
5.0.0 - 5.16.0
Medium
CVE-2026-73858
solspace/craft-freeform is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 5.0.0 - 5.10.13.
5.0.0 - 5.10.13
Medium
AIKIDO-2026-812289
solspace/craft-freeform is vulnerable to Missing Authorization in versions 5.0.0 - 5.15.26.
5.0.0 - 5.15.26
Medium
CVE-2026-26188
solspace/craft-freeform is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.14.6.
5.0.0 - 5.14.6
Low

Package versions

Maintainers

Solspace

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^4.0.0
—
—
nesbot/carbon
Version ^1.22.1|^2.19
—
—
symfony/finder
Version ^2.8|^3.0|^4.0|^5.0|^6.0
—
—
hashids/hashids
Version ^2.0|^3.0|^4.0
—
—
composer/composer
Version ^1.0|^2.0.13
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform