Healthy and suitable to use. It has a long release history, very recent and frequent maintenance, active contributors, clear licensing, and strong repository hygiene; the main caveats are install-time scripts and workflows without explicitly limited token permissions.
90%
Total Score
100
100
94
80
The package defines post-install and post-update Composer scripts, which add install-time behavior that consumers should review. The scripts are not shown as dangerous, so this is a limited supply-chain hygiene concern rather than a severe risk.
The repository uses Composer for builds, but no security scanning tool was detected. The missing scanner is a transparency and defense-in-depth gap, partially offset by the active repository and other workflow controls.
The only workflow lacks top-level token permissions, so its effective permissions are not explicitly constrained in the workflow metadata. No write permissions were detected, but explicit least-privilege declarations would improve transparency.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-171237 New vrana/adminer is vulnerable to Cross-Site Scripting (XSS) in versions 4.0.0 - 6.0.1. | 4.0.0 - 6.0.1 | Medium |
AIKIDO-2026-694710 New vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.0.0 - 6.0.1. | 6.0.0 - 6.0.1 | Medium |
AIKIDO-2026-191454 New vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF) in versions 4.16.0 - 6.0.1. | 4.16.0 - 6.0.1 | Medium |
AIKIDO-2026-597919 New vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.5.1 - 6.0.1. | 5.5.1 - 6.0.1 | Medium |
AIKIDO-2026-525866 vrana/adminer is vulnerable to Code Injection in versions 4.2.4 - 5.4.2. | 4.2.4 - 5.4.2 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.