Package Health

@livekit/protocol

Latest 1.52.1NPMNPM

92%

Total Score

healthy

Healthy release with active maintenance, strong packaging, and recent release notes.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The project uses npm scripts, esbuild, and Babel, but no security-scanning tools were detected; this is a modest transparency and assurance gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.

Workflow auditcaution

All four workflows were analyzed successfully, all 18 action references are pinned, and no concrete findings or untrusted sinks were detected. Three workflows use top-level write permissions, which is mild hygiene risk but not severe without an untrusted path.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10984 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@livekit/protocol is vulnerable to Cryptographic Downgrade in versions 1.45.8 - 1.45.8.
1.45.8 - 1.45.8
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@bufbuild/protobuf
Version ^1.10.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
2 years ago
Unpacked Size
5.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform