A Better Auth component for Convex.
78%
Total Score
75
100
88
83
Only four commits were recorded in the last three months, which is light for a package with frequent historical releases. This lowers confidence in current development momentum, though three active maintainers provide some compensation.
The repository has 97 open issues and 34 open pull requests; five issues and nine pull requests were opened in the last month, while none were closed or merged. This suggests a meaningful maintenance backlog.
The project uses TypeScript, Vitest, and npm scripts, and the source tree contains tests. No security scanning tooling was detected, leaving a modest security-process gap.
No repository security policy was found. This is a transparency and vulnerability-reporting gap, though it does not outweigh the active organization ownership and other project evidence.
Version 0.12.5 is not a stable-major release, but it is not a prerelease and recent releases contain no prerelease versions. The pre-1.0 major version warrants only limited caution for API stability.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-217795 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @convex-dev/better-auth is vulnerable to Denial of Service (DoS) in versions 0.7.0 - 0.12.4. | 0.7.0 - 0.12.4 | Low |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.0.0 | — | — |
jose Version ^6.1.0 | — | — |
remeda Version ^2.32.0 | — | — |
semver Version ^7.7.3 | — | — |
type-fest Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.