Tests, a changelog, and a security policy improve transparency. The four recent contributors and organization backing reduce handoff risk, while the prerelease target and unpinned workflow actions warrant checking before rollout.
88%
Total Score
100
88
67
Composer post-install and post-update scripts run during dependency operations. This is a mild supply-chain exposure, but the signal does not show that the scripts are harmful.
Composer is used for builds, but no security scanning tools were detected. That is a modest transparency gap for a maintained package, not evidence of abandonment.
This assessed release is beta.15.1 while the latest version is 5.16.0, so it is a prerelease and materially behind the current stable line.
Both workflows were analyzed successfully, use read-only permissions, and had no auditor findings or untrusted checkout or script-injection sinks. However, all 15 analyzed action references are unpinned, leaving avoidable build-integrity risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-73858 New solspace/craft-freeform is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 5.0.0 - 5.10.13. | 5.0.0 - 5.10.13 | Medium |
AIKIDO-2026-812289 solspace/craft-freeform is vulnerable to Missing Authorization in versions 5.0.0 - 5.15.26. | 5.0.0 - 5.15.26 | Medium |
CVE-2026-26188 solspace/craft-freeform is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.14.6. | 5.0.0 - 5.14.6 | Low |
CVE-2025-52122 solspace/craft-freeform is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 5.0.0 - 5.10.16. | 5.0.0 - 5.10.16 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0 | — | — |
nesbot/carbon Version ^1.22.1|^2.19 | — | — |
symfony/finder Version ^2.8|^3.0|^4.0|^5.0|^6.0 | — | — |
hashids/hashids Version ^2.0|^3.0|^4.0 | — | — |
composer/composer Version ^1.0|^2.0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.