flightphp/core v3.19.3 appears to be a healthy, mature dependency: it has a long release history, frequent recent releases, stable versioning, an active non-archived organization-backed repository, repository tests, security policy documentation, and a clean workflow-risk profile. The main concerns are strong concentration of recent commits in one contributor, an install-time post-install script, no configured security-scanning tool, and a workflow without top-level token permissions; these warrant review but do not outweigh the package's sustained maintenance and transparency.
88%
Total Score
90
100
94
80
A post-install-cmd script executes during installation, adding some supply-chain and reproducibility exposure even though no other evidence indicates dangerous workflow behavior.
Recent activity is highly concentrated: one contributor made 96.2% of commits, with only two contributors active. The organization backing provides some handoff capacity, but the concentration remains a genuine resilience concern.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap in the repository.
The only workflow lacks top-level token permissions, so its effective permissions are less explicit than recommended; however, no top-level write permissions were detected.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-719942 flightphp/core is vulnerable to Cross-Site Scripting (XSS) in versions 1.1.5 - 3.19.2. | 1.1.5 - 3.19.2 | High |
AIKIDO-2026-544773 flightphp/core is vulnerable to Authorization Bypass in versions 3.18.1 - 3.19.0. | 3.18.1 - 3.19.0 | High |
CVE-2026-42552 flightphp/core is vulnerable to Generation of Error Message Containing Sensitive Information in versions 0.0.0 - 3.18.1. | 0.0.0 - 3.18.1 | High |
CVE-2026-42551 flightphp/core is vulnerable to Interpretation Conflict in versions 0.0.0 - 3.18.1. | 0.0.0 - 3.18.1 | High |
CVE-2026-42550 flightphp/core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 3.18.1. | 0.0.0 - 3.18.1 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.