CASL is an isomorphic authorization JavaScript library which restricts what resources a given user is allowed to access
78%
Total Score
67
100
94
75
100
One contributor made all 8 recent commits, creating a meaningful continuity risk if that maintainer becomes unavailable.
There were 8 commits in the last 3 months, but all came from one active maintainer, so activity is present yet concentrated.
The project uses TypeScript and npm-based build tooling, but no security scanning tools were detected, leaving a modest transparency gap.
No repository security policy was found, which makes vulnerability reporting and response expectations less clear.
All 9 analyzed action references are unpinned, and one low-confidence high-severity github-env finding was reported; there were no untrusted checkouts or script injections, so this is workflow hygiene rather than a severe dependency risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-1774 @casl/ability is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 2.4.0 - 6.7.4. | 2.4.0 - 6.7.4 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
@ucast/mongo2js Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.