Its small runtime dependency set and documented security policy reduce adoption friction. The build workflow leaves all 10 actions unpinned, and no commits were recorded in the last 3 months, so pinning this release is prudent.
78%
Total Score
75
100
94
100
No commits or active maintainers were recorded in the last 3 months. The recent registry release partly offsets this, but the short-term source activity lull remains a maintenance caution.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe concern.
The single workflow was fully analyzed with no injection or high-severity findings, and it does not use broad top-level write permissions. However, all 10 action references are unpinned, leaving the build exposed to reference drift.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-46643 KnpLabs/knp-snappy is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 1.7.0. | 0.0.0 - 1.7.0 | High |
CVE-2026-46683 knplabs/knp-snappy is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.6.0. | 0.0.0 - 1.6.0 | Medium |
AIKIDO-2026-10857 knplabs/knp-snappy is vulnerable to Arbitrary File Deletion in versions 0.1.0 - 1.7.1. | 0.1.0 - 1.7.1 | Low |
CVE-2023-41330 knplabs/knp-snappy is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.4.2. | 0.0.0 - 1.4.2 | Critical |
CVE-2023-28115 knplabs/knp-snappy is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.4.2. | 0.0.0 - 1.4.2 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0||^3.0 | — | — |
symfony/process Version ^5.0||^6.0||^7.0||^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.