@clerk/nextjs 7.9.2 appears to be a very healthy dependency. It has a long release history with 6,396 releases and 2,083 releases in the last 12 months, is not deprecated, and is backed by an active organization-owned repository with 737 commits from 39 maintainers in the last three months. The package includes a license, type declarations, tests, a substantial artifact, npm provenance attestation, and no install-time lifecycle scripts. Repository security and workflow hygiene are also strong overall, with security scanning, a security policy, and no detected untrusted checkouts or script injection. The main minor concern is that three workflows lack top-level token permissions, although other workflows use read-only or job-level permissions and no dangerous workflow patterns were detected; the high recent prerelease share also warrants monitoring, but the assessed release itself is a stable major and not a prerelease.
97%
Total Score
100
100
100
90
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41248 @clerk/nextjs is vulnerable to Interpretation Conflict in versions 5.0.0 - 5.7.6, 6.0.0-snapshot.vb87a27f - 6.39.2 and 7.0.0 - 7.2.1. | 5.0.0 - 5.7.66.0.0-snapshot.vb87a27f - 6.39.27.0.0 - 7.2.1 | Critical |
AIKIDO-2024-10213 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @clerk/nextjs is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 5.2.14. | 0.0.1 - 5.2.14 | Low |
CVE-2024-22206 @clerk/nextjs is vulnerable to Improper Access Control in versions 4.7.0 - 4.29.3. | 4.7.0 - 4.29.3 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version 2.8.1 | — | — |
server-only Version 0.0.1 | — | — |
@clerk/react Version ^6.15.2 | — | — |
@clerk/shared Version ^4.31.1 | — | — |
@clerk/backend Version ^3.17.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.