Healthy and actively maintained, with strong release activity, repository support, tests, licensing, and build provenance. Review the concentrated commit activity and broad GitHub Actions permissions before adopting it in a high-value application.
84%
Total Score
88
100
63
100
One of 16 workflows uses pull_request_target, which warrants review because that trigger can grant elevated repository context. However, no untrusted checkouts or script-injection patterns were detected.
The package uses a prepare install lifecycle script. This adds some installation complexity and execution surface, but it is not severe on its own and the repository shows established build tooling.
One contributor made about 97% of the 218 recent commits, despite 5 active contributors. The organization backing reduces handoff risk, but the concentration still creates a meaningful continuity concern.
Six workflows declare top-level write permissions, ten omit top-level permissions, and none declare read-only permissions. The broad or implicit permission configuration is a repository hygiene concern, though it does not by itself show unsafe behavior.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10494 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @cashu/cashu-ts is vulnerable to Observable Timing Discrepancy in versions 2.5.0 - 3.6.2. | 2.5.0 - 3.6.2 | Low |
| Dependency | Last Release | Score |
|---|---|---|
@scure/base Version ^2.4.0 | — | — |
@scure/bip32 Version ^2.4.0 | — | — |
@noble/curves Version ^2.4.0 | — | — |
@noble/hashes Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.