This release appears to be a healthy, mature dependency with strong ongoing maintenance and release transparency. It has been released 1,235 times over more than four years, with 78 releases in the last 12 months, the repository was pushed very recently and is not archived, and repository activity is substantial across 30 active maintainers. The package has MIT licensing, extensive type declarations, npm provenance, no install-time lifecycle scripts, a security policy, and active issue and pull-request throughput. The main reservations are that the artifact omits tests and a changelog, although repository tests and GitHub Releases provide meaningful compensation, and many workflows lack explicit top-level permissions or use write permissions, which is a repository hygiene concern rather than evidence that the package is unsafe to depend on.
94%
Total Score
100
100
95
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10552 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @rspack/core is vulnerable to Malicious Code in versions 1.1.7 - 1.1.7. | 1.1.7 - 1.1.7 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
@rspack/binding Version 2.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.