Healthy and suitable to adopt, with an active project, frequent releases, strong repository practices, and clear documentation. It remains experimental before 1.0, and two workflows have top-level write permissions, so review upgrade compatibility and CI trust boundaries.
89%
Total Score
100
94
90
All workflows declare permissions, but two of the three grant top-level write permissions. Explicit permissions are better than missing declarations, though broad write access increases CI supply-chain exposure.
Version v0.8.1 is not a prerelease, but the project has not reached a stable major release, so API compatibility may still change. This is a manageable maturity caveat rather than an abandonment signal.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-523598 mcp/sdk is vulnerable to Uncontrolled Resource Consumption in versions 0.5.0 - 0.7.0. | 0.5.0 - 0.7.0 | High |
AIKIDO-2026-190480 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. mcp/sdk is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 0.6.0. | 0.1.0 - 0.6.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
symfony/uid Version ^5.4 || ^6.4 || ^7.3 || ^8.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.