@novu/js 3.19.2 appears to be a healthy dependency: it has a substantial release history, current non-deprecated stable-major status, active organizational backing, strong recent repository activity, broad contributor participation, build provenance, type declarations, and security tooling. The package artifact is well-formed for an SDK and avoids install-time lifecycle scripts. The main caution is GitHub Actions permission hygiene, with many analyzed workflows lacking top-level permissions and four declaring top-level write access, but this is mitigated by the absence of untrusted checkouts or script-injection findings and does not outweigh the strong maintenance and provenance evidence.
91%
Total Score
100
100
100
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-880038 @novu/js is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.17.0. | 0.0.1 - 3.17.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
clsx Version ^2.1.1 | — | — |
mitt Version ^3.0.1 | — | — |
solid-js Version ^1.9.4 | — | — |
partysocket Version ^1.1.4 | — | — |
@kobalte/core Version ^0.13.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.