It is MIT-licensed, includes a README and release notes, and has repository tests plus a security policy. The release workflow has two high-confidence template-injection findings, but the audit found no untrusted checkout or script injection and all actions are pinned.
94%
Total Score
100
100
83
The audit found two high-confidence template-injection findings in the release workflow and six workflows with top-level write permissions. However, there were no untrusted checkouts or script injections, all 45 analyzed action references were pinned, and the audit was complete.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11075 laravel/framework is vulnerable to CRLF Injection in versions 0.0.1 - 12.59.0 and 13.0.0 - 13.9.0. | 0.0.1 - 12.59.013.0.0 - 13.9.0 | High |
AIKIDO-2026-10659 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. laravel/framework is vulnerable to Insufficient Verification of Data Authenticity in versions 5.6.0 - 12.56.0 and 13.0.0 - 13.6.0. | 5.6.0 - 12.56.013.0.0 - 13.6.0 | High |
AIKIDO-2025-10363 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. laravel/framework is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 12.0.0 - 12.17.0. | 12.0.0 - 12.17.0 | Low |
CVE-2024-13919 laravel/framework is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 11.9.0 - 11.36.0. | 11.9.0 - 11.36.0 | Medium |
CVE-2024-13918 laravel/framework is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 11.9.0 - 11.36.0. | 11.9.0 - 11.36.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
brick/math Version ^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0 | — | — |
league/uri Version ^7.5.1 | — | — |
ramsey/uuid Version ^4.7 | — | — |
symfony/uid Version ^7.4.0 || ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.