Package Health

@inertiajs/core

A framework for creating server-driven single page apps.

Latest 3.8.0NPMNPM

88%

Total Score

healthy

Healthy: frequent releases and active maintenance outweigh concentrated commits and a minor workflow hygiene issue.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made about 72% of recent commits, creating concentration risk, although 13 contributors were active and the repository is organization-owned.

Workflow auditcaution

All 10 workflows were analyzed, all 41 action references are pinned, and no untrusted checkout or script-injection paths were found. The high-confidence adhoc-packages finding indicates a package is installed outside a lockfile, while the low-confidence cache-poisoning finding is hygiene-level only.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-465810 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@inertiajs/core is vulnerable to Prototype Pollution in versions 3.0.0 - 3.0.3.
3.0.0 - 3.0.3
Medium
AIKIDO-2026-854586 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@inertiajs/core is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.0 - 2.3.21 and 3.0.0 - 3.0.3.
1.0.0 - 2.3.213.0.0 - 3.0.3
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
es-toolkit
Version ^1.33.0
—
—
laravel-precognition
Version ^2.1.0
—
—
@jridgewell/trace-mapping
Version ^0.3.31
—
—

Weekly Downloads

Info

Last Published
7 days ago
Created
3 years ago
Unpacked Size
0.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform