Healthy and suitable to depend on. It has frequent releases, active development across 15 contributors, signed artifacts, and strong repository security practices; the main caveat is that the monorepo does not explicitly name this package in its README.
92%
Total Score
100
100
94
100
100
The repository name differs from the package name, which is normal for a monorepo, but its README does not mention this package; that leaves a minor transparency concern despite the coherent organization backing.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-787137 http4k-security-digest is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.0.1 - 4.50.0.0, 5.0.0.0 - 5.41.0.0 and 6.0.0.0 - 6.49.0.0. | 0.0.1 - 4.50.0.05.0.0.0 - 5.41.0.06.0.0.0 - 6.49.0.0 | Medium |
AIKIDO-2026-149241 http4k-security-digest is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.1 - 4.50.0.0, 5.0.0.0 - 5.41.0.0 and 6.0.0.0 - 6.49.0.0. | 0.0.1 - 4.50.0.05.0.0.0 - 5.41.0.06.0.0.0 - 6.49.0.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.http4k:http4k-core Version 6.60.0.0 | — | — |
org.http4k:http4k-security-core Version 6.60.0.0 | — | — |
org.jetbrains.kotlin:kotlin-stdlib Version 2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.