Package Health

neuron-core/neuron-ai

A unified layer for building AI-native applications in PHP.

Latest 4.1.7PackagistPackagist

90%

Total Score

healthy

Frequent stable releases and active project maintenance outweigh the workflow pinning gap.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

All three workflows were analyzed and use read-only permissions with no untrusted checkouts or script injection. However, 19 of 20 action references are unpinned, a genuine reproducibility and supply-chain hygiene concern; the cache-poisoning findings are low-confidence hygiene signals.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-11009 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
neuron-core/neuron-ai is vulnerable to CRLF Injection in versions 2.4.0 - 3.14.6.
2.4.0 - 3.14.6
High
AIKIDO-2026-11008 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
neuron-core/neuron-ai is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.4.0 - 3.14.6.
2.4.0 - 3.14.6
High
CVE-2025-67510
neuron-core/neuron-ai is vulnerable to Execution with Unnecessary Privileges in versions 0.0.0 - 2.8.11.
0.0.0 - 2.8.11
Critical
AIKIDO-2025-10852
neuron-core/neuron-ai is vulnerable to SQL Injection in versions 1.11.4 - 2.8.11.
1.11.4 - 2.8.11
High

Package versions

Maintainers

Valerio Barbera

Direct Dependencies

DependencyLast ReleaseScore
psr/event-dispatcher
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 hours ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform