Documentation, a changelog, and release notes are present, and the repository is not archived. No install-time scripts are declared; the missing security scanning tooling is the main remaining hygiene gap.
82%
Total Score
88
86
100
One contributor made about 96% of the 122 recent commits, creating meaningful continuity risk despite four additional active contributors.
Composer is used for builds, but no security scanning tools were detected, leaving a maintenance and dependency-hygiene gap.
This release is a beta, so compatibility risk is higher than for a stable release, although only 20% of recent releases are prereleases and the major line is established.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-76089 New verbb/formie is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 3.0.0 - 3.1.31 and 0.0.0 - 2.2.23. | 0.0.0 - 2.2.233.0.0 - 3.1.31 | High |
CVE-2026-76087 New verbb/formie is vulnerable to Authorization Bypass Through User-Controlled Key in versions 3.0.0 - 3.1.31 and 0.0.0 - 2.2.23. | 0.0.0 - 2.2.233.0.0 - 3.1.31 | High |
CVE-2026-76086 New verbb/formie is vulnerable to Missing Authorization in versions 3.0.0 - 3.1.31 and 0.0.0 - 2.2.23. | 0.0.0 - 2.2.233.0.0 - 3.1.31 | High |
AIKIDO-2026-967385 verbb/formie is vulnerable to Missing Authorization in versions 0.0.1 - 3.1.37. | 0.0.1 - 3.1.37 | Medium |
AIKIDO-2026-678815 verbb/formie is vulnerable to Server-Side Template Injection (SSTI) in versions 1.0.0 - 2.2.29 and 3.0.0 - 3.1.36. | 1.0.0 - 2.2.293.0.0 - 3.1.36 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
verbb/auth Version ^2.0.44 | — | — |
verbb/base Version ^3.0.11 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
verbb/tiptap Version ^1.0.1 | — | — |
dompdf/dompdf Version ^1.0.2 || ^2.0.3 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.