Spring Security
84%
Total Score
healthy
Healthy release, supported by active maintenance and signed publishing despite milestone status and workflow hygiene concerns.
One contributor made about 77% of recent commits, creating concentration risk, although seven other contributors were active and organization backing provides some handoff capacity.
The repository name does not match the package and its README does not mention the package, creating a caution that the artifact-to-repository link is not explicit; the organization-owned Spring repository makes a monorepo explanation plausible but does not remove the gap.
The assessed version is a prerelease milestone, so compatibility may change before a stable release even though the major line is established.
All 12 workflows were analyzed, all 28 action references are pinned, and most workflows use read-only permissions. However, the audit found a high-confidence template-injection issue and several high-confidence secrets-inherit findings, while four workflows have top-level write permissions.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10468 spring-security-taglibs is vulnerable to Authorization Bypass in versions 0.0.1 - 6.2.7 and 6.3.0 - 6.3.4. | 0.0.1 - 6.2.76.3.0 - 6.3.4 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.security:spring-security-acl Version 7.2.0-M2 | — | — |
org.springframework.security:spring-security-core Version 7.2.0-M2 | — | — |
org.springframework.security:spring-security-web Version 7.2.0-M2 | — | — |
org.springframework:spring-aop Version 7.1.0-M2 | — | — |
org.springframework:spring-beans Version 7.1.0-M2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.