@peculiar/x509 is an easy to use TypeScript/Javascript library based on @peculiar/asn1-schema that makes generating X.509 Certificates and Certificate Requests as well as validating certificate chains easy
88%
Total Score
90
50
94
80
100
The package has 11 runtime dependencies, mostly related @peculiar ASN.1 components, which is a notable dependency surface for a security-sensitive library but appears coherent with its stated X.509 functionality.
Two contributors were active, but the top contributor made about 78% of recent commits, leaving a meaningful concentration risk; organization backing partly mitigates the risk of a single-person dependency.
The repository uses TypeScript, Rollup, and Vitest for build and test workflows, but no security-scanning tools were detected; the missing scanning is a hygiene gap rather than evidence of abandonment.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures for a cryptographic library.
Two workflows lack top-level permission declarations and the release workflow grants top-level write access, increasing the potential impact of workflow compromise even though no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.8.1 | — | — |
tsyringe Version ^4.10.0 | — | — |
pvtsutils Version ^1.3.6 | — | — |
@peculiar/asn1-cms Version ^2.9.4 | — | — |
@peculiar/asn1-csr Version ^2.9.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.