Healthy and suitable to depend on, with strong release history and active project maintenance. Review the alpha release carefully because the repository has no security policy or automated security-scanning tooling reported.
84%
Total Score
100
100
88
75
The package runs a pre-autoload-dump install-time script, which adds some installation complexity and execution surface, though this is limited to a standard Composer lifecycle hook.
Composer build tooling is present, but no security-scanning tools were detected; that is a transparency and assurance gap for a large platform.
No repository security policy was found, leaving vulnerability-reporting expectations and disclosure guidance unclear despite the project's active maintenance.
The package has a stable-major release profile and only 5% recent prereleases, although the assessed alpha-named release warrants extra compatibility review.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-426017 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 10.5.0 - 10.6.16, 11.0.0 - 11.3.16 and 11.4.0 - 11.4.6. | 10.5.0 - 10.6.1611.0.0 - 11.3.1611.4.0 - 11.4.6 | Medium |
AIKIDO-2026-869158 drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 10.6.12, 11.0.0 - 11.3.13 and 11.4.0 - 11.4.3. | 0.0.1 - 10.6.1211.0.0 - 11.3.1311.4.0 - 11.4.3 | Medium |
AIKIDO-2026-357148 drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.2.0 - 11.3.13 and 11.4.0 - 11.4.3. | 11.2.0 - 11.3.1311.4.0 - 11.4.3 | Medium |
AIKIDO-2026-186793 drupal/core is vulnerable to Information Disclosure in versions 0.0.0 - 10.6.12, 11.0.0 - 11.3.13 and 11.4.0 - 11.4.3. | 0.0.0 - 10.6.1211.0.0 - 11.3.1311.4.0 - 11.4.3 | Medium |
AIKIDO-2026-543762 drupal/core is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11. | 0.0.0 - 10.5.1110.6.0 - 10.6.1011.0.0 - 11.2.13 +1 more | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.28.0 | — | — |
mck89/peast Version ^1.17.4 | — | — |
symfony/mime Version ^8.1 | — | — |
symfony/yaml Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.