This release appears healthy and suitable to depend on: it has a long release history, frequent recent releases, stable versioning, active repository maintenance, organizational backing, repository tests and changelog coverage, build provenance, and no deprecation or workflow-risk indicators. The main residual concern is contributor concentration, with one contributor responsible for about 85% of recent commits, although three other contributors remain active and the organization-owned project provides some maintenance continuity. The package artifact is intentionally compact and lacks its own README, tests, and changelog, but the linked repository supplies those materials.
91%
Total Score
90
100
100
100
100
The leading contributor made about 85% of recent commits, creating a genuine concentration risk; however, three other contributors were active and the organization-owned repository provides some capacity for handoff.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-61789 allure-commandline is vulnerable to Cross-Site Scripting (XSS) in versions 2.44.0 - 2.44.1. | 2.44.0 - 2.44.1 | Medium |
AIKIDO-2026-209802 allure-commandline is vulnerable to Path Traversal in versions 0.0.1 - 2.44.1. | 0.0.1 - 2.44.1 | Medium |
CVE-2026-55846 io.qameta.allure:allure-commandline is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.38.1. | 0.0.0 - 2.38.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.slf4j:slf4j-jdk14 Version 2.0.18 | — | — |
com.beust:jcommander Version 1.82 | — | — |
com.fasterxml.jackson.core:jackson-databind Version 2.22.2 | — | — |
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml Version 2.22.2 | — | — |
commons-io:commons-io Version 2.22.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.