Ergonomic Framework for Human
78%
Total Score
75
100
100
75
100
The repository recorded 11 commits from two active maintainers in three months, showing ongoing work but a relatively light recent commit pace.
The repository is receiving issues and pull requests, but only three issues were closed and no pull requests were merged in the last month, indicating some backlog pressure.
All five analyzed action references are unpinned and one workflow grants top-level write access. The two cache-poisoning findings are low-confidence hygiene warnings, with no untrusted checkout or script-injection paths found.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-654904 elysia is vulnerable to Denial of Service (DoS) in versions 0.3.0 - 1.4.28. | 0.3.0 - 1.4.28 | High |
CVE-2026-31865 elysia is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 1.4.27. | 0.0.0 - 1.4.27 | Medium |
CVE-2026-30837 elysia is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 1.4.26. | 0.0.0 - 1.4.26 | High |
AIKIDO-2026-10019 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. elysia is vulnerable to Observable Timing Discrepancy in versions 1.0.0 - 1.4.19. | 1.0.0 - 1.4.19 | Low |
CVE-2025-66457 elysia is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.4.18. | 0.0.0 - 1.4.18 | High |
| Dependency | Last Release | Score |
|---|---|---|
cookie Version ^1.1.1 | — | — |
memoirist Version ^0.4.0 | — | — |
exact-mirror Version ^0.2.7 | — | — |
fast-decode-uri-component Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.