Scriban 7.4.0 appears actively maintained and mature: it has 141 releases over more than 10 years, 30 releases in the last 12 months, a stable non-prerelease version, a substantial package file tree, and only three runtime dependencies. However, the release has no declared or packaged license, no packaged tests or changelog, and no declared source-repository link, which reduces legal and maintenance transparency; repository activity and other operational health signals were not available, so confidence is moderate rather than high.
72%
Total Score
100
75
100
No declared license was found, and the artifact contains no license file. This creates a genuine legal and transparency concern for dependents.
The artifact includes a substantial README, but it contains no packaged tests or changelog, leaving testing and release-history documentation gaps. The README and source files provide useful context, but do not fully compensate for the missing validation and change documentation.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-477016 Scriban is vulnerable to Sandbox Bypass in versions 0.0.0 - 6.6.0. | 0.0.0 - 6.6.0 | Critical |
AIKIDO-2026-377213 Scriban is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 7.1.0. | 0.1.0 - 7.1.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
microsoft.csharp Version [4.7.0, ) | — | — |
system.text.json Version [10.0.8, ) | — | — |
system.threading.tasks.extensions Version [4.6.3, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.