The repository has active, distributed contributors, tests, security scanning, and a security policy. The only notable weakness is that all 31 workflow action references are unpinned, which reduces build reproducibility.
90%
Total Score
100
100
100
100
100
Both workflows were fully analyzed with no reported audit findings or untrusted checkouts, and one scopes permissions at job level. However, all 31 action references are unpinned, a reproducibility and update-integrity weakness.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-424329 New json is vulnerable to Denial of Service (DoS) in versions 20070829 - 20260522. | 20070829 - 20260522 | Medium |
CVE-2023-5072 org.json:json is vulnerable to Improperly Implemented Security Check for Standard in versions 0.0.0 - 20230618. | 0.0.0 - 20230618 | High |
CVE-2022-45688 org.json:json is vulnerable to Out-of-bounds Write in versions 0.0.0 - 20230227. | 0.0.0 - 20230227 | High |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.