Real-time communications library with full support for the Session Initiation Protocol (SIP) and WebRTC. No wrappers and no native libraries required.
84%
Total Score
healthy
Healthy: sustained releases and active repository work outweigh the workflow pinning gap.
No build tool or security scanning tool was detected, leaving less automated assurance around builds and security hygiene.
All six workflows were analyzed with no dangerous triggers, untrusted checkouts, injections, or audit findings, but all 21 action references are unpinned, leaving actions exposed to upstream changes.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-464784 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. SIPSorcery is vulnerable to Denial of Service (DoS) in versions 5.2.0 - 10.0.15. | 5.2.0 - 10.0.15 | Medium |
AIKIDO-2026-16594 SIPSorcery is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.8. | 0.0.1 - 10.0.8 | Medium |
AIKIDO-2026-997995 SIPSorcery is vulnerable to Improper Certificate Validation in versions 0.0.1 - 10.0.15. | 0.0.1 - 10.0.15 | High |
AIKIDO-2026-400608 SIPSorcery is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.13. | 0.0.1 - 10.0.13 | Medium |
AIKIDO-2026-302152 SIPSorcery is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.13. | 0.0.1 - 10.0.13 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sipsorcerymedia.abstractions Version [10.0.17, ) | — | — |
bouncycastle.cryptography Version [2.7.0, ) | — | — |
concentus Version [2.2.2, ) | — | — |
dnsclient Version [1.8.0, ) | — | — |
makaretu.dns.multicast Version [0.27.0, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.