Extracting archives made easy
82%
Total Score
70
100
94
80
50
No build attestation or trusted-publisher metadata is present, leaving release origin less verifiable; this is a transparency gap rather than evidence that the release is unsafe.
Only one registry account has publish access, creating publishing continuity risk, although repository activity shows that the same maintainer is actively maintaining the project.
The package and repository are owned by the same individual rather than an organization, so the single-maintainer concentration is a genuine continuity concern.
One contributor made all 12 commits in the last three months, so maintenance depends heavily on a single person and could be vulnerable to interruption.
The repository has no security policy, making vulnerability reporting and response expectations less transparent.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-130799 @xhmikosr/decompress is vulnerable to Path Traversal in versions 0.0.1 - 10.2.1 and 11.0.0 - 11.1.3. | 0.0.1 - 10.2.111.0.0 - 11.1.3 | Critical |
CVE-2026-53486 @xhmikosr/decompress is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 10.2.1 and 11.0.0 - 11.1.3. | 0.0.0 - 10.2.111.0.0 - 11.1.3 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
strip-dirs Version ^3.0.0 | — | — |
graceful-fs Version ^4.2.11 | — | — |
@xhmikosr/decompress-tar Version ^9.0.2 | — | — |
@xhmikosr/decompress-targz Version ^9.0.1 | — | — |
@xhmikosr/decompress-unzip Version ^8.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.