The package has a clear MIT license, a focused dependency set, release notes for this version, and organization backing. Repository security coverage is limited, and workflow dependencies are unpinned.
66%
Total Score
67
100
94
75
The repository had zero commits and zero active maintainers in the last three months, indicating a meaningful recent maintenance gap.
There were no new or closed issues or pull requests in the last month, while three issues and two pull requests remain open; this supports a modest maintenance concern.
Composer build tooling is present, but no security scanning tools were detected, leaving security-maintenance coverage limited.
The repository has no published security policy, reducing transparency for vulnerability reporting and response expectations.
The single workflow was fully analyzed with no detected dangerous findings, but all three action references are unpinned, weakening build reproducibility and supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10397 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. appsero/client is vulnerable to Improper Access Control in versions 1.0 - 2.0.0. | 1.0 - 2.0.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.