88%
Total Score
healthy
Healthy: active releases and a maintained, security-conscious source project support dependable adoption.
The repository name does not match the package and its README does not mention @milkdown/crepe, creating some uncertainty about package-to-repository traceability; the organization-owned monorepo context partly explains the mismatch.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-250781 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @milkdown/crepe is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 7.21.0 - 7.21.0. | 7.21.0 - 7.21.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
vue Version ^3.5.20 | — | — |
clsx Version ^2.0.0 | — | — |
katex Version ^0.18.0 | — | — |
dompurify Version ^3.2.5 | — | — |
lodash-es Version ^4.17.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.