This release appears healthy and suitable for dependency use. It has a strong release cadence with 157 releases over 711 days and 63 releases in the last 12 months, is stable rather than prerelease, is not deprecated, and has active repository maintenance with 27 commits and 10 active maintainers in the last 3 months. The organization-backed repository includes tests, changelog support, a security policy, extensive source scaffolding, and a balanced contributor distribution; the package also has an MIT license, TypeScript declarations, npm provenance, and no install-time lifecycle scripts. The main reservations are incomplete GitHub Actions permission declarations, one workflow with top-level write permissions, absent detected repository security-scanning tooling, and an issue backlog that is growing faster than it is closing, but these do not outweigh the broader evidence of active maintenance and transparent provenance.
89%
Total Score
90
100
95
90
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-263108 @opennextjs/cloudflare is vulnerable to Improper Handling of URL Encoding in versions 0.3.0 - 1.20.1. | 0.3.0 - 1.20.1 | High |
CVE-2026-3125 @opennextjs/cloudflare is vulnerable to Use of Incorrectly-Resolved Name or Reference in versions 0.0.0 - 1.17.1. | 0.0.0 - 1.17.1 | High |
CVE-2025-6087 @opennextjs/cloudflare is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.3.0. | 0.0.0 - 1.3.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
glob Version ^12.0.0 | — | — |
yargs Version ^18.0.0 | — | — |
ci-info Version ^4.2.0 | — | — |
ts-tqdm Version ^0.8.6 | — | — |
enquirer Version ^2.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.