92%
Total Score
healthy
Healthy release with active maintenance, strong packaging, and recent release notes.
The project uses npm scripts, esbuild, and Babel, but no security-scanning tools were detected; this is a modest transparency and assurance gap.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
All four workflows were analyzed successfully, all 18 action references are pinned, and no concrete findings or untrusted sinks were detected. Three workflows use top-level write permissions, which is mild hygiene risk but not severe without an untrusted path.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10984 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @livekit/protocol is vulnerable to Cryptographic Downgrade in versions 1.45.8 - 1.45.8. | 1.45.8 - 1.45.8 | High |
| Dependency | Last Release | Score |
|---|---|---|
@bufbuild/protobuf Version ^1.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.