Audited & minimal JS implementation of elliptic curve cryptography
91%
Total Score
75
100
100
100
100
The repository is owned by an individual rather than an organization, so the concentrated contributor activity has less organizational redundancy to offset it.
One contributor made about 94% of the last 3 months' commits, leaving maintenance highly concentrated despite a second active contributor; this is a continuity caution.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-26118 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @noble/curves is vulnerable to Observable Timing Discrepancy in versions 0.2.0 - 2.2.0. | 0.2.0 - 2.2.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
@noble/hashes Version 2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.