Typed artifacts, release notes for this patch, and no install scripts improve day-to-day trust. The organization-backed project also has four active contributors and clean workflow auditing.
84%
Total Score
100
94
83
100
The repository name does not match this package and its README does not mention it, so the package-to-source relationship is less transparent even though a monorepo can legitimately host subpackages.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-850060 @tinyhttp/cookie-signature is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.1 - 2.1.1. | 0.0.1 - 2.1.1 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.