@node-red/editor-api 5.0.7 appears to be a healthy, mature dependency. It has a long release history with 150 releases and 29 releases in the last 12 months, is not deprecated, and is backed by an active, non-archived organizational repository with recent commits, multiple active contributors, tests, releases, security tooling, and strong workflow permission hygiene. The main limitations are absent type declarations, no build provenance attestation, and the linked monorepo not explicitly naming this package in its README; these reduce transparency or developer ergonomics but are outweighed by the package's established monorepo structure and strong maintenance evidence.
90%
Total Score
100
100
95
100
50
No registry build attestation or trusted-publisher provenance is available, leaving a supply-chain transparency gap despite the package's otherwise strong repository evidence.
The linked repository name does not match the package and its README does not mention the package, creating a repository-association transparency concern. The package documentation identifies the Node-RED modules as a monorepo, which explains the mismatch but does not remove the observed gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-970261 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @node-red/editor-api is vulnerable to Cross-Site Scripting (XSS) in versions 2.1.0 - 4.1.11 and 5.0.0 - 5.0.1. | 2.1.0 - 4.1.115.0.0 - 5.0.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 7.5.11 | — | — |
cors Version 2.8.6 | — | — |
mime Version 3.0.0 | — | — |
clone Version 2.1.2 | — | — |
multer Version 2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.