Rive's canvas based web api.
82%
Total Score
healthy
Frequent releases, active contributors, and verified publishing outweigh workflow pinning and security-policy gaps.
Four of five publish-access accounts use the rive.app domain, and the organization-backed project makes that concentration normal; the single gmail.com account, luigi-rosso, is a minor account-hygiene caution but not evidence of limited maintenance capacity.
No build tool or security-scanning tool was detected in the collected repository metadata, leaving a modest process and assurance gap.
The repository has no SECURITY.md or other detected security policy, reducing transparency about vulnerability reporting and response.
All 13 action references are unpinned and one workflow grants top-level write access, creating workflow hygiene concerns. High-confidence template-injection findings in number.yaml and publish.yml are worth review, but no untrusted checkout or script-injection sink was found, so this is not a severe health risk on its own.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10177 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @rive-app/canvas is vulnerable to Heap-based Buffer Overflow in versions 2.1.1 - 2.19.2. | 2.1.1 - 2.19.2 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.