A Laravel publishing platform
78%
Total Score
healthy
Healthy, with active maintenance and strong project hygiene despite single-contributor activity and unpinned workflow actions.
A post-autoload-dump lifecycle script runs during installation, adding execution during dependency setup. This is a modest supply-chain and installation-complexity concern, not evidence that the release is unfit.
The registry package and repository are owned by the same user account, and the repository is user-owned rather than organization-owned. This matches the package identity but provides limited institutional backing.
One contributor made all recent commits, with a 100% share. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.
The repository recorded 114 commits in the last three months, showing strong recent activity. All reported activity came from one active maintainer, which limits resilience.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout, injection, or high-severity findings. However, all 25 action references are unpinned, leaving builds exposed to future action changes.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-26845 New austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.0.0 - 7.1.0. | 7.0.0 - 7.1.0 | Low |
AIKIDO-2026-265353 austintoddj/canvas is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.0.0 - 7.0.0. | 7.0.0 - 7.0.0 | High |
CVE-2017-8298 austintoddj/canvas is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.3.0 - 3.3.0. | 3.3.0 - 3.3.0 | Medium |
CVE-2017-1000507 austintoddj/canvas is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.4.2. | 0.0.0 - 3.4.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.0|^13.0 | — | — |
illuminate/auth Version ^12.0|^13.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/mail Version ^12.0|^13.0 | — | — |
illuminate/view Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.