Package Health

@simple-git/argv-parser

Latest 2.0.1NPMNPM

68%

Total Score

caution

Usable with caveats: repository commits stopped for three months despite ongoing release and pull-request activity.

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

The repository records zero commits and zero active maintainers over the last three months, a meaningful maintenance warning despite recent releases and pull-request merges.

Security policycaution

No repository security policy was found, leaving vulnerability reporting guidance unclear for a package that documents and addresses security-sensitive behavior.

Workflow auditcaution

All four workflows were analyzed with no high-confidence audit findings or untrusted checkout and injection sinks, but all 12 action references are unpinned and one workflow has top-level write permissions, weakening build reproducibility and least privilege.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-102829 New
@simple-git/argv-parser is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 2.0.1.
0.0.0 - 2.0.1
Critical
AIKIDO-2026-455143 New
@simple-git/argv-parser is vulnerable to Command Injection in versions 0.0.1 - 2.0.0.
0.0.1 - 2.0.0
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@simple-git/args-pathspec
Version ^1.0.4
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
6 months ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform