The package includes tests, release notes, a substantial README, and a security policy, supporting dependable maintenance. Its workflow uses read-only permissions but leaves all three actions unpinned, and the release has no identifiable license.
84%
Total Score
100
100
88
88
Neither the package nor the linked repository provides a recognized license declaration or license file. This is a real transparency and adoption concern, despite the otherwise well-documented project.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest assurance gap rather than evidence of abandonment or unsafe behavior by itself.
The single workflow was fully analyzed, uses read-only permissions, and has no detected high- or medium-confidence findings or untrusted execution sinks. However, all 3 referenced actions are unpinned, leaving a supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-682474 New craftcms/cloud is vulnerable to Missing Authorization in versions 1.0.0 - 3.11.0. | 1.0.0 - 3.11.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
bref/bref Version ^3 | — | — |
league/uri Version ^7.6 | — | — |
craftcms/cms Version ^4.6 || ^5 | — | — |
phlak/semver Version ^4.1 | — | — |
aws/aws-sdk-php Version ^3.342.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.