A framework for creating server-driven single page apps.
88%
Total Score
healthy
Healthy: frequent releases and active maintenance outweigh concentrated commits and a minor workflow hygiene issue.
One contributor made about 72% of recent commits, creating concentration risk, although 13 contributors were active and the repository is organization-owned.
All 10 workflows were analyzed, all 41 action references are pinned, and no untrusted checkout or script-injection paths were found. The high-confidence adhoc-packages finding indicates a package is installed outside a lockfile, while the low-confidence cache-poisoning finding is hygiene-level only.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-465810 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @inertiajs/core is vulnerable to Prototype Pollution in versions 3.0.0 - 3.0.3. | 3.0.0 - 3.0.3 | Medium |
AIKIDO-2026-854586 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @inertiajs/core is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.0 - 2.3.21 and 3.0.0 - 3.0.3. | 1.0.0 - 2.3.213.0.0 - 3.0.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
es-toolkit Version ^1.33.0 | — | — |
laravel-precognition Version ^2.1.0 | — | — |
@jridgewell/trace-mapping Version ^0.3.31 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.