Package Health

@clerk/express

Clerk server SDK for usage with Express

Latest 2.1.77NPMNPM

89%

Total Score

healthy

Active, organization-backed package with a strong release record; workflow audit shows limited CI hygiene concerns.

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match this sub-package and its README does not mention @clerk/express. That is a caution about package-to-repository linkage, although the organization-owned monorepo context partly explains the name mismatch.

Workflow auditcaution

All 16 workflows were analyzed with no untrusted checkout or script-injection findings, and all 87 action references are pinned. The audit did find three high-confidence template-injection findings and four high-confidence ad hoc package installs, which are CI hygiene concerns but not independently severe supply-chain evidence.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-395995 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@clerk/express is vulnerable to Authentication Bypass in versions 0.0.1 - 2.1.24.
0.0.1 - 2.1.24
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version 2.8.1
—
—
@clerk/shared
Version ^4.39.1
—
—
@clerk/backend
Version ^3.23.1
—
—

Weekly Downloads

Info

Last Published
9 hours ago
Created
2 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform