The most comprehensive authentication framework for TypeScript.
86%
Total Score
healthy
Healthy: frequent releases and active organization-backed maintenance outweigh workflow permission concerns.
The repository name does not match @better-auth/core and its README does not mention the package. This may be normal for a monorepo, but the absence of either match or mention weakens package-to-source transparency.
All 20 workflows were analyzed, all use read-only permissions, and all 78 action references are pinned. However, three high-confidence github-app findings report blanket installation permissions, and trusted-publishing was also flagged; these are workflow hygiene and supply-chain concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10548 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @better-auth/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.3.18 - 1.6.5. | 1.3.18 - 1.6.5 | High |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.5.4 | — | — |
@standard-schema/spec Version ^1.1.0 | — | — |
@opentelemetry/semantic-conventions Version ^1.41.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.