league/commonmark 2.10.1 appears to be a healthy, mature dependency: it has more than 12 years of release history, 145 releases, nine releases in the last 12 months, a stable non-prerelease version, an active non-archived organization-backed repository, substantial recent commit and pull-request activity, and a matching repository with comprehensive documentation and tests. The main residual concerns are that repository security-scanning tools were not detected and one workflow lacks top-level token permissions, while the registry maintainer count is only one; these are mitigated by the organization ownership, active multi-contributor development, repository security policy, and otherwise restrictive workflow configuration.
94%
Total Score
100
100
94
90
Composer build tooling is present, but no security-scanning tools were detected; this is a transparency and defense-in-depth gap rather than evidence of abandonment.
Two workflows declare read-only permissions and none declare top-level write permissions; one workflow lacks top-level permissions, leaving a modest configuration gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-550503 league/commonmark is vulnerable to Denial of Service (DoS) in versions 1.5.0 - 2.9.2. | 1.5.0 - 2.9.2 | High |
AIKIDO-2026-280543 league/commonmark is vulnerable to Cross-Site Scripting (XSS) in versions 2.7.0 - 2.9.0. | 2.7.0 - 2.9.0 | High |
AIKIDO-2026-319775 league/commonmark is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 2.9.0. | 0.6.0 - 2.9.0 | High |
AIKIDO-2026-676279 league/commonmark is vulnerable to Denial of Service (DoS) in versions 1.5.0 - 2.9.0. | 1.5.0 - 2.9.0 | High |
AIKIDO-2026-849032 league/commonmark is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.8.3. | 2.0.0 - 2.8.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
league/config Version ^1.1.1 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
symfony/polyfill-php80 Version ^1.16 | — | — |
symfony/deprecation-contracts Version ^2.1 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.