A clear README, repository tests, release notes, and an MIT license support adoption. The workflow is fully audited with read-only permissions, but its two action references are unpinned and the project has no published security policy.
70%
Total Score
83
100
94
83
The repository recorded no commits and no active maintainers during the last three months. This is a maintenance concern, although the recent release provides some compensating evidence.
Composer is used for the build, but no security scanning tooling is reported. The absence of scanning is a hygiene gap rather than evidence of abandonment.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a library that parses multipart content.
The only workflow was fully analyzed, uses read-only permissions, and has no dangerous sinks or audit findings. However, both action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10404 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. riverline/multipart-parser is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.1.1. | 2.0.0 - 2.1.1 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.