Package Health

@casl/ability

CASL is an isomorphic authorization JavaScript library which restricts what resources a given user is allowed to access

Latest 7.0.1NPMNPM

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made all 8 recent commits, creating a meaningful continuity risk if that maintainer becomes unavailable.

Repo commit activitycaution

There were 8 commits in the last 3 months, but all came from one active maintainer, so activity is present yet concentrated.

Repo toolingcaution

The project uses TypeScript and npm-based build tooling, but no security scanning tools were detected, leaving a modest transparency gap.

Security policycaution

No repository security policy was found, which makes vulnerability reporting and response expectations less clear.

Workflow auditcaution

All 9 analyzed action references are unpinned, and one low-confidence high-severity github-env finding was reported; there were no untrusted checkouts or script injections, so this is workflow hygiene rather than a severe dependency risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-1774
@casl/ability is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 2.4.0 - 6.7.4.
2.4.0 - 6.7.4
Critical

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@ucast/mongo2js
Version ^2.0.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
8 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform