Healthy and actively maintained, with strong project backing, frequent releases, broad contributor activity, tests, and security tooling. Build attestations are absent and several workflows lack explicit permissions, so review your pinning and deployment controls before adopting it.
91%
Total Score
100
50
100
75
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-889201 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @strapi/admin is vulnerable to Insufficient Session Expiration in versions 0.0.1 - 5.50.2. | 0.0.1 - 5.50.2 | Medium |
CVE-2026-22706 @strapi/admin is vulnerable to Insufficient Session Expiration in versions 0.0.0 - 5.33.2. | 0.0.0 - 5.33.2 | Low |
CVE-2024-52588 @strapi/admin is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 4.25.2. | 0.0.0 - 4.25.2 | Medium |
CVE-2023-38507 @strapi/admin is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.0 - 4.12.1. | 0.0.0 - 4.12.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
qs Version 6.15.3 | — | — |
koa Version 2.16.4 | — | — |
ora Version 5.4.1 | — | — |
yup Version 0.32.9 | — | — |
zod Version 4.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.