Clear documentation, type declarations, licensing, and release provenance make integration straightforward. The repository also has tests, a security policy, and active organizational support.
86%
Total Score
88
100
83
100
One contributor made about 86% of the recent commits, creating concentration risk; the organization-backed project and six other recent contributors partly reduce that concern.
All six workflows were analyzed with no reported audit findings or untrusted checkouts, but 47 of 56 action references are unpinned and two workflows grant top-level write permissions, leaving reproducibility and token-scope hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-876449 @libp2p/webrtc is vulnerable to Denial of Service (DoS) in versions 5.1.0 - 6.0.27. | 5.1.0 - 6.0.27 | High |
| Dependency | Last Release | Score |
|---|---|---|
p-defer Version ^4.0.1 | — | — |
p-event Version ^7.0.0 | — | — |
get-port Version ^7.1.0 | — | — |
p-timeout Version ^7.0.0 | — | — |
main-event Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.