Simple Social Sharing for Nuxt
78%
Total Score
75
100
95
67
100
The repository is owned by an individual user rather than an organization, so the concentrated maintainer activity is not offset by visible organizational backing.
All 23 recent commits came from one contributor, so maintenance continuity depends heavily on a single person.
The project uses TypeScript and npm scripts for builds, but no security scanning tools were observed, leaving a modest tooling gap.
No repository security policy was found, reducing transparency about how vulnerabilities should be reported.
All eight analyzed action references are unpinned and three workflows grant top-level write permissions. The low-confidence high-severity cache-poisoning finding is a hygiene concern, but no untrusted checkout or script-injection sink was found.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10724 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @stefanobartoletti/nuxt-social-share is vulnerable to Improper Input Validation in versions 1.0.0 - 2.0.0. | 1.0.0 - 2.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
defu Version ^6.1.7 | — | — |
@nuxt/kit Version ^4.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.