@astrojs/vercel 11.0.10 appears to be a healthy dependency: it has a long and active release history, stable versioning, current repository activity, broad contributor participation, organizational backing, licensing, bundled types, npm provenance, and no deprecation or install-time scripts. The main reservation is workflow permission hygiene, since several repository workflows lack top-level permissions and three declare write access, but the repository also uses security scanning and shows no analyzed untrusted-checkout or script-injection findings. Overall, the package presents low maintenance and transparency risk for adoption.
96%
Total Score
100
100
100
90
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-750327 @astrojs/vercel is vulnerable to Authorization Bypass in versions 10.0.3 - 11.0.2. | 10.0.3 - 11.0.2 | Medium |
CVE-2026-73424 @astrojs/vercel is vulnerable to Unintended Proxy or Intermediary ('Confused Deputy') in versions 10.0.3 - 11.0.3. | 10.0.3 - 11.0.3 | Medium |
CVE-2026-33768 @astrojs/vercel is vulnerable to Unintended Proxy or Intermediary ('Confused Deputy') in versions 0.0.0 - 10.0.2. | 0.0.0 - 10.0.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
esbuild Version ^0.28.0 | — | — |
tinyglobby Version ^0.2.15 | — | — |
@vercel/nft Version ^1.10.2 | — | — |
@vercel/analytics Version ^2.0.1 | — | — |
@vercel/functions Version ^3.7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.