The project has clear release notes, repository tests, a license, signed Maven provenance, and active organizational support. Pinning all 21 GitHub Actions references would improve workflow hygiene.
88%
Total Score
100
100
100
100
100
All five workflows were analyzed with no audit findings or untrusted checkout and script-injection paths. However, all 21 action references are unpinned, creating a workflow supply-chain hygiene gap, and one workflow grants top-level write permission.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-107635 mcp-core is vulnerable to Denial of Service (DoS) in versions 0.18.0 - 0.18.3, 1.0.0 - 1.1.3 and 2.0.0 - 2.0.0. | 0.18.0 - 0.18.31.0.0 - 1.1.32.0.0 - 2.0.0 | Medium |
AIKIDO-2026-935066 mcp-core is vulnerable to Denial of Service (DoS) in versions 0.18.0 - 0.18.3, 1.0.0 - 1.1.3 and 2.0.0 - 2.0.0. | 0.18.0 - 0.18.31.0.0 - 1.1.32.0.0 - 2.0.0 | High |
CVE-2026-35568 io.modelcontextprotocol.sdk:mcp-core is vulnerable to Origin Validation Error in versions 0.0.0 - 1.0.0. | 0.0.0 - 1.0.0 | High |
CVE-2026-34237 io.modelcontextprotocol.sdk:mcp-core is vulnerable to Permissive Cross-domain Security Policy with Untrusted Domains in versions 1.1.0 - 1.1.0, 1.0.0 - 1.0.0 and 0.0.0 - 0.18.3. | 0.0.0 - 0.18.31.0.0 - 1.0.01.1.0 - 1.1.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.slf4j:slf4j-api Version 2.0.16 | — | — |
com.fasterxml.jackson.core:jackson-annotations Version 2.21 | — | — |
io.projectreactor:reactor-core Version 3.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.