The small second contributor and missing security policy leave less redundancy and disclosure guidance. Tests, licensing, automated security checks, and a recent release history provide useful support.
78%
Total Score
83
100
50
One contributor made about 92% of the recent commits, leaving substantial concentration risk. The second contributor remains active and the organization backing provides some handoff capacity, so this is a caution rather than a severe risk.
The repository has no published security policy, so users lack clear documented guidance for reporting vulnerabilities or understanding the project's response process.
All three workflows were analyzed, but all 23 action references are unpinned, and the audit found two high-confidence medium-severity secrets-inherit findings; one workflow also has top-level write permissions. These are meaningful workflow hygiene and credential-scope concerns, though no untrusted checkout or script injection was found.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-783925 simplesamlphp/xml-common is vulnerable to XML External Entity Injection (XXE) in versions 2.7.2 - 2.7.5, 2.8.0 - 2.8.1 and 3.0.0 - 3.0.0. | 2.7.2 - 2.7.52.8.0 - 2.8.13.0.0 - 3.0.0 | High |
CVE-2024-52596 simplesamlphp/xml-common is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.0 - 1.20. | 0.0.0 - 1.20 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ~1.0 | — | — |
simplesamlphp/assert Version ~3.0 | — | — |
simplesamlphp/composer-xmlprovider-installer Version ~1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.