The project has a long release history, active recent development, tests, and a security policy. Its workflow references are not pinned, so build reproducibility is weaker than the otherwise strong maintenance picture.
88%
Total Score
100
100
100
83
All seven workflows were analyzed without file failures, and permissions are scoped at job level or read-only with no top-level write access. However, all 23 action references are unpinned, which weakens reproducibility; the low-confidence cache-poisoning finding is hygiene rather than a standalone severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10547 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. horstoeko/zugferd is vulnerable to Information Disclosure in versions 0.1.11 - 1.0.98. | 0.1.11 - 1.0.98 | Low |
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5|^6|^7|^8 | — | — |
setasign/fpdf Version ^1 | — | — |
setasign/fpdi Version ^2 | — | — |
jms/serializer Version ^3 | — | — |
symfony/finder Version ^5|^6|^7|^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.