The repository is actively maintained with six contributors, tests, a changelog, security policy, and signed Maven provenance. The artifact is a compiled Maven library, so its missing README and tests are expected; verify the license wording and pin workflow actions.
87%
Total Score
83
100
93
100
100
The artifact includes a license file and the repository also has one, so licensing is present. However, the registry declaration says Bouncy Castle Licence while the artifact detector identifies MIT, creating a license-identification mismatch to verify.
One contributor made about 75% of recent commits, but five other contributors were active during the same period. The concentration is a maintenance caution, not a severe abandonment signal.
The only workflow was fully analyzed with no audit findings, no untrusted checkouts, and job-level permissions. All 3 action references are unpinned, which weakens build reproducibility and action supply-chain protection.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-956848 bcmail-jdk18on is vulnerable to Improper Certificate Validation in versions 0.0.1 - 1.84.0. | 0.0.1 - 1.84.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.bouncycastle:bcpkix-jdk18on Version 1.85 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.