Reliable form builder that's ready for wherever your project takes you.
88%
Total Score
100
88
67
Composer post-install and post-update scripts run during dependency operations. This is a mild supply-chain exposure, but the signal does not show that the scripts are harmful.
Composer is used for builds, but no security scanning tools were detected. That is a modest transparency gap for a maintained package, not evidence of abandonment.
This assessed release is beta.15.1 while the latest version is 5.16.0, so it is a prerelease and materially behind the current stable line.
Both workflows were analyzed successfully, use read-only permissions, and had no auditor findings or untrusted checkout or script-injection sinks. However, all 15 analyzed action references are unpinned, leaving avoidable build-integrity risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-833597 New solspace/craft-freeform is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.0.0 - 5.16.1. | 5.0.0 - 5.16.1 | High |
AIKIDO-2026-470568 New solspace/craft-freeform is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 5.0.0 - 5.16.0. | 5.0.0 - 5.16.0 | Medium |
CVE-2026-73858 solspace/craft-freeform is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 5.0.0 - 5.10.13. | 5.0.0 - 5.10.13 | Medium |
AIKIDO-2026-812289 solspace/craft-freeform is vulnerable to Missing Authorization in versions 5.0.0 - 5.15.26. | 5.0.0 - 5.15.26 | Medium |
CVE-2026-26188 solspace/craft-freeform is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0 - 5.14.6. | 5.0.0 - 5.14.6 | Low |
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0 | — | — |
nesbot/carbon Version ^1.22.1|^2.19 | — | — |
symfony/finder Version ^2.8|^3.0|^4.0|^5.0|^6.0 | — | — |
hashids/hashids Version ^2.0|^3.0|^4.0 | — | — |
composer/composer Version ^1.0|^2.0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.