Clear ownership, licensing, tests, and a long release history provide useful context. Prefer a current stable release over this beta when compatibility permits.
68%
Total Score
67
86
75
All recent commits come from one contributor, concentrating current maintenance capacity; organization backing partly offsets the handoff risk.
Only 1 commit from 1 active maintainer appeared in the last 3 months, indicating a thin recent maintenance footprint despite the broader release history.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
This release is a beta while the latest version is stable 2.15.4, so the assessed version is less mature than the project's current stable line.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-27131 putyourlightson/craft-sprig is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 2.0.0 - 2.15.2 and 3.0.0 - 3.7.2. | 2.0.0 - 2.15.23.0.0 - 3.7.2 | Medium |
AIKIDO-2025-10242 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. putyourlightson/craft-sprig is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.13.1 and 3.0.0 - 3.5.2. | 2.0.0 - 2.13.13.0.0 - 3.5.2 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0 | — | — |
ivopetkov/html5-dom-document-php Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.