Clear documentation, source tests, and a licensed artifact make integration straightforward. Pin the two unpinned workflow actions when possible; no severe workflow findings were reported.
88%
Total Score
88
100
100
50
The repository is owned by an individual user rather than an organization, so maintenance relies on the observed small contributor group; current activity partly offsets that limitation.
No repository security policy was found, which weakens the project's documented vulnerability-reporting process, though other maintenance and tooling signals are positive.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving a modest build-reproducibility and action-substitution gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-565301 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. gregwar/captcha is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in versions 1.0.0 - 2.0.0. | 1.0.0 - 2.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.