Aider
Open-source CLI coding assistant with deep Git integration and model-agnostic BYOK architecture supporting 30+ LLM providers including local models.
Dimension breakdown
Score · confidenceOpen-source CLI coding assistant with deep Git integration and model-agnostic BYOK architecture supporting 30+ LLM providers including local models. Aider Polyglot Leaderboard remains the industry-standard benchmark for LLM code editing (Claude Opus 4.5 leads at 89.4%, GPT-5 88.0%; Opus 4.8 not yet posted on the polyglot board).
Strong for terminal-native developers wanting git-native workflows and vendor-API resilience (BYOK insulates from single-vendor disruption).
Unpatched prompt injection vulnerability (GitHub Issue #5058, opened Apr 21 2026) — ~37 days open with zero maintainer comments — lets Architect mode commit backdoored code via README manipulation.
Note: this is a GitHub issue, NOT a CVE; CVE-2026-5058 is an unrelated aws-mcp-server flaw. Evaluate trust-boundary risk before production use on untrusted repos.
Single-maintainer bus factor; release cadence resumed (multiple named releases May–June 2026: Sonnet 4/Opus 4 support, model-alias updates) after a prior multi-month gap since v0.86.0 (Aug 2025).
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
Critical security vuln
securityTemporaryUnpatched critical security vulnerability
Caps Enterprise / Compliance at 25
Removed when — CVE patched and verified, or security incident resolved with post-mortem published
Status rationale
Tracked because Aider demonstrates strong agentic capabilities (multi-step, self-correction, 30+ LLM support), maintains the industry-standard Aider Polyglot benchmark, and shows active commits (through May 22 2026). However, an unpatched prompt injection vulnerability (GitHub Issue #5058, zero maintainer engagement after ~37 days) creates active security risk for architect mode users.
Zero enterprise features (no SSO, audit, compliance), extreme bus factor concentration, and no path to enterprise adoption block advancement. Release cadence resumed May–June 2026 (Sonnet 4/Opus 4 support, model-alias updates) after a prior gap since v0.86.0 (Aug 2025) — the movementTrigger 'formal release cadence resumes' criterion is now met.
The critical-security-vuln cap constrains Compliance ≤ 5.
Movement triggers
Upgrade if: prompt injection vulnerability patched with post-mortem (Issue #5058), enterprise features introduced (SSO, audit logs, compliance), additional core maintainers join. [Release cadence resumed May–June 2026 — that upgrade trigger is now met.] Downgrade if: commits stop entirely (>90 days triggers stalled-development cap), Paul Gauthier becomes unavailable, security vulnerability exploited in the wild, community exodus begins, open issue backlog crosses 2,000 without remediation.
Risks & limitations
Critical Security Vuln
ModerateRadar cap: critical-security-vuln
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category