Package Health

@clerk/backend

Clerk Backend SDK - REST Client for Backend API & JWT verification utilities

Latest 3.23.2NPMNPM

88%

Total Score

healthy

Active releases, broad maintenance, signed provenance, and strong packaging outweigh limited workflow hygiene concerns.

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention @clerk/backend, creating some uncertainty about package-to-repository linkage. The organization-owned monorepo context makes a name mismatch ordinary, but the absent README mention still warrants caution.

Workflow auditcaution

All 16 workflows were analyzed with no untrusted checkout or script-injection findings, and all 88 action references are pinned. High-confidence template-injection findings and several ad hoc package installs remain workflow hygiene concerns, though no dangerous trigger-and-sink combination was observed.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-125473 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@clerk/backend is vulnerable to Authentication Bypass in versions 2.33.0 - 3.11.6.
2.33.0 - 3.11.6
Medium
CVE-2026-34076
@clerk/backend is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.0.0 - 3.2.2.
3.0.0 - 3.2.2
High
CVE-2025-53548
@clerk/backend is vulnerable to Insufficient Verification of Data Authenticity in versions 2.0.0 - 2.4.0.
2.0.0 - 2.4.0
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version 2.8.1
—
—
@clerk/shared
Version ^4.40.0
—
—
standardwebhooks
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
3 years ago
Unpacked Size
4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform