The project has a long release history, current activity, clear licensing, and documented security reporting. Its release notes, repository tests, and organization backing provide useful maintenance context.
74%
Total Score
100
50
100
83
The release declares 16 runtime dependencies, including platform extensions and several libraries; this is a meaningful dependency surface but not excessive for a full URL-shortening application.
A post-update-cmd lifecycle script runs during dependency updates, adding some execution-path complexity, although this signal alone does not show harmful behavior.
All five workflows were analyzed, but all 15 action references are unpinned; the audit also found high-confidence unpinned container images and blanket app-token permissions. A pull_request_target trigger is present without an untrusted checkout or script-injection sink, so these are serious workflow-hygiene cautions rather than a standalone health verdict.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63135 yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.5.1 - 1.10.3. | 1.5.1 - 1.10.3 | High |
CVE-2020-27388 yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.5 - 1.8. | 1.5 - 1.8 | Medium |
CVE-2022-0088 yourls/yourls is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.0 - 1.8.2. | 0.0.0 - 1.8.2 | Low |
CVE-2021-3785 yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.2. | 0.0.0 - 1.8.2 | Medium |
CVE-2021-3783 yourls/yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.2. | 0.0.0 - 1.8.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aura/sql Version ^6.0 | — | — |
pomo/pomo Version ^1.4 | — | — |
geoip2/geoip2 Version ^2.10 | — | — |
rmccue/requests Version ^2.0 | — | — |
ozh/bookmarkletgen Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.