Stempler, HTML markup processor and template engine framework
76%
Total Score
healthy
Healthy, with strong release continuity and organization backing offsetting a concentrated contributor base.
All 9 commits in the last three months came from one contributor, creating a concentrated maintenance risk. The organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe risk.
No security policy was found in the repository, which is a transparency gap for reporting vulnerabilities, but it is not evidence of abandonment by itself.
Both workflows were analyzed with no dangerous audit findings, unsafe checkout, or script injection. However, both action references are unpinned, leaving a modest reproducibility and action-integrity gap; missing top-level permissions blocks are not concerning here because neither workflow requests top-level write access.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-28946 spiral/stempler is vulnerable to Cross-Site Scripting (XSS) in versions 2.7.0 - 3.17.1. | 2.7.0 - 3.17.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
spiral/core Version ^3.17.2 | — | — |
myclabs/deep-copy Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.