Package Health

@nestjs/platform-fastify

Nest - modern, fast, powerful node.js web framework (@platform-fastify)

Latest 12.1.2NPMNPM

91%

Total Score

healthy

Healthy: active releases and a well-maintained organization-backed repository outweigh minor workflow and package-mapping cautions.

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention the package, creating some uncertainty about the exact package-to-repository mapping; the organization-owned monorepo context partly explains the name mismatch but not the absent mention.

Workflow auditcaution

Both workflows were analyzed, use read-only permissions, and contain no untrusted checkout or script-injection findings. However, all 4 analyzed action references are unpinned, a minor reproducibility and supply-chain hygiene concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-742982
@nestjs/platform-fastify is vulnerable to Authentication bypass via path-scoped middleware skip in versions 6.0.0 - 11.2.3 and 12.0.0 - 12.0.1.
6.0.0 - 11.2.312.0.0 - 12.0.1
High
CVE-2026-54281
@nestjs/platform-fastify is vulnerable to Incorrect Authorization in versions 0.0.0 - 11.1.23.
0.0.0 - 11.1.23
High
CVE-2026-33011
@nestjs/platform-fastify is vulnerable to Always-Incorrect Control Flow Implementation in versions 0.0.0 - 11.1.15.
0.0.0 - 11.1.15
High
AIKIDO-2026-10258
@nestjs/platform-fastify is vulnerable to URL normalization bypass in versions 11.0.0 - 11.1.13.
11.0.0 - 11.1.13
High
CVE-2025-69211
@nestjs/platform-fastify is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 11.1.10.
0.0.0 - 11.1.10
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version 2.8.1
—
—
fastify
Version 5.12.5
—
—
find-my-way
Version 9.9.0
—
—
@fastify/cors
Version 11.3.0
—
—
path-to-regexp
Version 8.4.2
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
7 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform