Healthy and suitable to depend on, with active organizational maintenance and a well-documented, typed package. The main caveats are missing build attestations and security policy documentation, plus incomplete workflow permission declarations.
88%
Total Score
100
100
89
75
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-808118 @descope/nextjs-sdk is vulnerable to Authentication Bypass in versions 0.0.1 - 0.15.55. | 0.0.1 - 0.15.55 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
@descope/node-sdk Version 2.8.0 | — | — |
@descope/react-sdk Version 3.3.4 | — | — |
@descope/core-js-sdk Version 2.72.0 | — | — |
@descope/web-component Version 4.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.