This release appears healthy and suitable for dependency use. It has a long release history with four releases in the last 12 months, is not deprecated, uses a stable major version, has Maven PGP signature provenance, and is backed by an active, non-archived organization-owned repository with substantial recent commit and issue activity. Repository tests, changelog, security policy, build tooling, and security scanning compensate for the minimal artifact scaffolding. The main reservations are concentrated commit activity, the repository not explicitly naming this package in its README, and a workflow lacking top-level token permissions; these are hygiene and resilience concerns rather than evidence of abandonment.
88%
Total Score
90
100
94
90
100
One contributor made about 72.5% of recent commits, creating concentration risk, although two additional contributors each contributed about 13.1% and the repository is organization-owned.
The repository name does not match this package and its README does not mention the package, which raises a package-to-repository traceability concern. The name mismatch is compatible with a multi-module repository, but the lack of a README mention remains a caution.
The analyzed CodeQL workflow lacks top-level permissions and uses job-level permissions only; this is a workflow-hardening gap, though no top-level write permissions were observed.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-912141 bcjmail-jdk15to18 is vulnerable to Improper Certificate Validation in versions 0.0.1 - 1.84.0. | 0.0.1 - 1.84.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.bouncycastle:bcpkix-jdk15to18 Version 1.86 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.