gitsafehub
github.com/sickcodes/hestiacp ↗

sickcodes/hestiacp

scanned 2026-08-15 · git 01f69ac
2 of 6 checks flagged a security issue
🟡 Worth a look
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies12Known OSS vulnerabilities13Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 12 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2023-52892 In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2023-52892). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-32935 phpseclib is a PHP secure communications library. Projects using versi ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-32935). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44167 phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0 ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-44167). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-27354 An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0 ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2024-27354). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-27355 An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0 ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2024-27355). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-55599 phpseclib is a PHP secure communications library. From 0.1.1 until 1.0 ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-55599). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-64500 Symfony is a PHP framework for web and console applications and a set ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2025-64500). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-50345 symfony/http-foundation is a module for the Symphony PHP framework whi ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2024-50345). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45067 ### Description `Symfony\Component\Mime\Address` is the value-object ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-45067). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45070 Symfony is a PHP framework for web and console applications and a set ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-45070). Fix: Update that package to its patched version.
  • Minor CVE-2026-40194 phpseclib is a PHP secure communications library. Starting in 0.1.1 an ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-40194). Fix: Update that package to its patched version.
  • Minor CVE-2026-46644 Symfony Polyfill backports PHP features and provides compatibility lay ...
    install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-46644). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 13 found

Your dependencies cross-checked against the OSV vulnerability database.

  • Worth fixing GHSA-2528-jw5q-ww88 phpseclib: guardrails needed on isPrime and randomPrime
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2024-27354). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3qpq-r242-jqj7 phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-44167). Fix: Update that package to its patched version.
  • Worth fixing GHSA-94g3-g5v7-q4jg phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-32935). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f2qx-66wf-wvvx phpseclib guardrails needed on OID length
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2024-27355). Fix: Update that package to its patched version.
  • Worth fixing GHSA-ff7q-6vwh-v9m4 Name confusion in x509 Subject Alternative Name fields
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2023-52892). Fix: Update that package to its patched version.
  • Worth fixing GHSA-m557-wrgg-6rp4 phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-55599). Fix: Update that package to its patched version.
  • Worth fixing GHSA-vvj3-c3rp-c85p PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-24765). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3rg7-wf37-54rm Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2025-64500). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qpmx-3rfj-7rhv Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-45067). Fix: Update that package to its patched version.
  • Worth fixing GHSA-vqc8-7275-q272 Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-45070). Fix: Update that package to its patched version.
  • Minor GHSA-r854-jrxh-36qx phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-40194). Fix: Update that package to its patched version.
  • Minor GHSA-mrqx-rp3w-jpjp Symfony vulnerable to open redirect via browser-sanitized URLs
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2024-50345). Fix: Update that package to its patched version.
  • Minor GHSA-2xf4-cg6j-vhgq symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form
    /workdirs/scan-86a0c4f4-f4de-4fef-a12a-f019aaa05da6/install/deb/filemanager/filegator/composer.lock
    A package you depend on has a known security hole (CVE-2026-46644). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.