Package Health

@fastify/reply-from

@fastify/reply-from 12.6.5 appears healthy and suitable to depend on. It has a long release history with regular recent releases, a stable non-prerelease version, active repository maintenance, five recent contributors with balanced commit participation, organization backing, extensive tests, clear documentation, an MIT license, type declarations, security policy, Dependabot coverage, and read-only workflow permissions. The absence of build provenance attestation and a packaged changelog are minor transparency gaps, but the repository's GitHub Releases and active development provide meaningful compensation; no deprecation, archival, risky workflow behavior, or install-time lifecycle scripts were observed.

Latest 12.6.5NPMNPM

94%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is present, which is a modest release-transparency gap, though it does not by itself indicate poor maintenance.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-247087
@fastify/reply-from is vulnerable to Confused Deputy in versions 8.3.1 - 12.6.3.
8.3.1 - 12.6.3
High
AIKIDO-2026-659663 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@fastify/reply-from is vulnerable to Denial of Service (DoS) in versions 7.0.0 - 12.6.2.
7.0.0 - 12.6.2
Low
CVE-2026-33805
@fastify/reply-from is vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax in versions 0.0.0 - 12.6.1.
0.0.0 - 12.6.1
High
CVE-2025-66415
@fastify/reply-from is vulnerable to Unintended Proxy or Intermediary ('Confused Deputy') in versions 0.0.0 - 12.4.0.
0.0.0 - 12.4.0
Medium
CVE-2023-51701
@fastify/reply-from is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 0.0.0 - 9.6.0.
0.0.0 - 9.6.0
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
undici
Version ^7.0.0
toad-cache
Version ^3.7.0
end-of-stream
Version ^1.4.4
@fastify/error
Version ^4.0.0
fastify-plugin
Version ^6.0.0

Weekly Downloads

Info

Last Published
20 days ago
Created
4 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform