This release appears usable but has only a short operating history of 147 days and three releases, so long-term maintenance maturity is not yet established. It is a stable, non-deprecated Maven release with a small runtime dependency surface, license files, and Maven PGP signing, which are meaningful positives. The lack of a declared source repository reduces transparency and leaves repository-level maintenance evidence unavailable; the compact artifact structure is consistent with a compiled library, but does not independently demonstrate sustained project backing.
68%
Total Score
100
80
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-160085 New springdoc-openapi-starter-webflux-mcp is vulnerable to Exposure of Data Element to Wrong Session in versions 3.0.3 - 3.1.0. | 3.0.3 - 3.1.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springdoc:springdoc-openapi-starter-common-mcp Version 3.1.1 | — | — |
org.springdoc:springdoc-openapi-starter-webflux-api Version 3.1.1 | — | — |
io.micrometer:context-propagation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.