Package Health

@inquirer/external-editor

Edit a string with the users preferred text editor using $VISUAL or $ENVIRONMENT

Latest 3.0.6NPMNPM

78%

Total Score

healthy

Healthy, with a repository-package mismatch and highly concentrated recent contributions as notable caveats.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made about 81% of recent commits, so maintenance depends heavily on a single person despite seven other contributors being active.

Repo package mentioncaution

The repository name differs from the package name and its README does not mention this package, leaving the package-to-source relationship less transparent than expected for a dependency.

Workflow auditcaution

All five workflows were analyzed with no untrusted checkout or script-injection findings and all action references pinned; one high-confidence low-severity finding reports installing a package outside a lockfile, which is a limited hygiene concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-674364 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@inquirer/external-editor is vulnerable to Path traversal in versions 0.0.1 - 3.0.2.
0.0.1 - 3.0.2
Low

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
chardet
Version ^2.1.1
—
—
iconv-lite
Version ^0.7.2
—
—

Weekly Downloads

Info

Last Published
7 days ago
Created
1 year ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform