StackRadar

plausible-analytics 0.4.2 Helm chart

imioVerified publisher

Scored 15 Sept 2026

A Helm Chart for Plausible Analytics - Simple, open-source, lightweight (< 1 KB) and privacy-friendly web analytics alternative to Google Analytics.

Version 0.4.2 1 year agoapp version 3.0.1 0Artifact Hub

plausible-analytics 0.4.2 deploys 5 container images: library/postgres, bitnamilegacy/clickhouse, ghcr.io/plausible/community-edition and bitnamilegacy/postgresql. Across them, 935 findings0 critical, 7 high. The highest contribution is ALPINE-CVE-2025-6965 in sqlite 3.48.0-r0, fixed in 3.48.0-r3.

Radar Score

10,15207172756

935 findings over 5 of 5 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
library/postgres17.6-alpine0117841,047
bitnamilegacy/clickhouse24.12.401401922,429
ghcr.io/plausible/community-editionv3.0.10223691,144
bitnamilegacy/clickhouse24.12.3-debian-12-r101401922,429
bitnamilegacy/postgresql17.6.0-debian-12-r002522193,103

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

478 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-11979libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowBIT-postgresql-2025-12818postgresql@17.6.0-013.23.0
LowDEBIAN-CVE-2026-86140libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowALPINE-CVE-2026-34743xz@5.6.3-r15.8.3-r0
LowDEBIAN-CVE-2026-34743xz-utils@5.4.1-0.25.4.1-1+deb12u1
LowDEBIAN-CVE-2026-5704tar@1.34+dfsg-1.2+deb12u1no fix listed
LowGHSA-pq67-6m6q-mj2vurllib3@1.26.202.5.0
LowDEBIAN-CVE-2026-3184util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2026-7010perl@5.36.0-7+deb12u1no fix listed
LowDEBIAN-CVE-2026-19487perl@5.36.0-7+deb12u1no fix listed
LowGHSA-65pc-fj4g-8rjxidna@3.103.15
LowDEBIAN-CVE-2026-89158pcre2@10.42-110.42-1+deb12u1
LowDEBIAN-CVE-2011-3374apt@2.6.1no fix listed
LowGHSA-vp96-hxj8-p424pyopenssl@24.1.026.0.0
LowDEBIAN-CVE-2025-27587openssl@3.0.15-1~deb12u1no fix listed
LowALPINE-CVE-2026-42769openssl@3.5.4-r03.5.7-r0
LowDEBIAN-CVE-2013-4392systemd@252.33-1~deb12u1no fix listed
LowALPINE-CVE-2026-78408util-linux@2.41-r92.41.6-r1
LowDEBIAN-CVE-2026-78408util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2026-41989libgcrypt20@1.10.1-31.10.1-3+deb12u1
LowDEBIAN-CVE-2023-45322libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u2
LowGO-2026-4981stdlib@go1.24.61.25.10
LowDEBIAN-CVE-2023-31439systemd@252.38-1~deb12u1no fix listed
LowGO-2026-4977stdlib@go1.24.61.25.10
LowALPINE-CVE-2026-76957expat@2.7.0-r02.8.4-r0
LowDEBIAN-CVE-2023-31437systemd@252.38-1~deb12u1no fix listed
LowDEBIAN-CVE-2025-68973gnupg2@2.2.40-1.12.2.40-1.1+deb12u2
LowGO-2026-4986stdlib@go1.24.61.25.10
LowGO-2026-4918stdlib@go1.24.61.25.10
LowGO-2026-4337stdlib@go1.24.61.24.13
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u92.36-9+deb12u14
LowGHSA-qccp-gfcp-xxvcurllib3@1.26.202.7.0
LowDEBIAN-CVE-2023-31438systemd@252.38-1~deb12u1no fix listed
LowDEBIAN-CVE-2023-39615libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u2
LowDEBIAN-CVE-2026-1757libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u6
LowGO-2026-4601stdlib@go1.24.61.25.8
LowALPINE-CVE-2026-56403expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56404expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56405expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56408expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56406expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56407expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56410expat@2.7.0-r02.8.2-r0
LowALPINE-CVE-2026-56411expat@2.7.0-r02.8.2-r0
LowDEBIAN-CVE-2026-19499glibc@2.36-9+deb12u9no fix listed
LowDEBIAN-CVE-2026-78410util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2026-89161pcre2@10.42-110.42-1+deb12u1
LowALPINE-CVE-2025-4516python3@3.12.10-r03.12.10-r1
LowGO-2026-5026stdlib@go1.24.61.25.13
LowBIT-gdal-2026-8084gdal@3.11.33.13.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.2latest1 year ago3.0.10717275610,152

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/imio/plausible-analytics.svg)](https://charts.stackradar.io/charts/imio/plausible-analytics)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.