Healthy and suitable to use, with strong release history, current maintenance, clear licensing, tests, and a well-matched repository. The main concern is that all recent commits came from one contributor, which increases maintenance continuity risk.
82%
Total Score
70
100
100
100
The registry namespace and repository are owned by the same individual account, so the package has clear ownership but lacks the redundancy of organization backing.
One contributor made all 120 recent commits, with a 100% share, creating a clear continuity risk if that contributor becomes unavailable.
Only 2 issues are open and 9 pull requests are open, but none of the 2 issues were closed and no pull requests were merged in the last month; this suggests some response or review backlog.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-265353 austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.0.0 - 7.0.0. | 7.0.0 - 7.0.0 | High |
CVE-2017-8298 austintoddj/canvas is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.3.0 - 3.3.0. | 3.3.0 - 3.3.0 | Medium |
CVE-2017-1000507 austintoddj/canvas is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.2. | 0.0.0 - 3.4.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.0|^13.0 | — | — |
illuminate/auth Version ^12.0|^13.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/mail Version ^12.0|^13.0 | — | — |
illuminate/view Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.