Edit a string with the users preferred text editor using $VISUAL or $ENVIRONMENT
78%
Total Score
healthy
Healthy, with a repository-package mismatch and highly concentrated recent contributions as notable caveats.
One contributor made about 81% of recent commits, so maintenance depends heavily on a single person despite seven other contributors being active.
The repository name differs from the package name and its README does not mention this package, leaving the package-to-source relationship less transparent than expected for a dependency.
All five workflows were analyzed with no untrusted checkout or script-injection findings and all action references pinned; one high-confidence low-severity finding reports installing a package outside a lockfile, which is a limited hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-674364 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @inquirer/external-editor is vulnerable to Path traversal in versions 0.0.1 - 3.0.2. | 0.0.1 - 3.0.2 | Low |
| Dependency | Last Release | Score |
|---|---|---|
chardet Version ^2.1.1 | — | — |
iconv-lite Version ^0.7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.