Fast Rust-based bundler for the web with a modernized webpack API
68%
Total Score
caution
Usable with caveats: active maintenance is offset by high-confidence workflow risks involving untrusted checkout and template injection.
All 24 workflows were analyzed and action references are fully pinned, but release-debug.yml combines workflow_run with an untrusted checkout, while the audit reports high-confidence template-injection findings and broad write permissions elsewhere. These are material automation supply-chain concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10552 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @rspack/core is vulnerable to Malicious Code in versions 1.1.7 - 1.1.7. | 1.1.7 - 1.1.7 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
@rspack/binding Version 2.2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.