This release appears healthy and suitable to depend on. It has a stable major version, very frequent recent releases, no registry deprecation, valid Apache 2.0 licensing, Maven PGP signing, and a non-archived organization-backed repository with strong recent activity: 1,451 commits from 100 active maintainers in three months, substantial issue and pull-request throughput, and broad contributor distribution. The artifact itself is minimal and lacks packaged documentation or tests, but the linked repository contains tests, extensive project scaffolding, GitHub Releases, security tooling, and a security policy, which compensates for those artifact-level gaps. The main cautions are several workflows without explicit top-level token permissions and one detected script-injection pattern, so CI/CD hardening should be reviewed before adopting it in a highly sensitive build environment.
91%
Total Score
100
100
70
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-802290 New ui is vulnerable to Cross-Site Scripting (XSS) in versions 0.21.19 - 1.3.35. | 0.21.19 - 1.3.35 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
com.google.guava:guava Version * | — | — |
commons-io:commons-io Version * | — | — |
org.apache.commons:commons-lang3 Version * | — | — |
io.swagger.core.v3:swagger-annotations Version * | — | — |
com.google.code.findbugs:jsr305 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.