It has a signed Maven build, tests, and a changelog in the source project. The organization-backed repository also has a security policy and active security scanning.
90%
Total Score
100
100
94
100
100
The repository name does not match this package and its README does not mention it. Although a monorepo name mismatch is ordinary, the absence of a package mention creates some uncertainty about package-to-repository correspondence.
The single analyzed workflow completed without audit findings and scopes permissions at job level, but all 3 action references are unpinned, leaving avoidable update and supply-chain hygiene risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-76591 bctls-jdk14 is vulnerable to Improper Certificate Validation in versions 1.61 - 1.84. | 1.61 - 1.84 | High |
AIKIDO-2026-117282 bctls-jdk14 is vulnerable to Denial of Service (DoS) in versions 1.61 - 1.84. | 1.61 - 1.84 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.bouncycastle:bcutil-jdk14 Version 1.85 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.