Javascript implementation of zip for nodejs with support for electron original-fs. Allows user to create or extract zip files both in memory or to/from disk
88%
Total Score
67
100
95
90
50
No build provenance attestation or trusted-publisher identity is present, leaving release origin less independently verifiable.
Only one registry account has publish access, creating some publishing continuity and account-compromise risk, although repository activity shows the project is actively maintained.
The repository is owned by an individual rather than an organization, so long-term continuity depends on a relatively narrow project base; this is partly offset by recent release and repository activity.
All three workflows lack top-level permissions declarations, which weakens least-privilege clarity; none declares top-level write access, limiting the observed risk.
Version 0.6.1 is not a stable-major release, which is a modest compatibility concern, but it is not a prerelease and recent prerelease usage is absent.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-102282 adm-zip is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.0.0 - 0.6.0. | 0.0.0 - 0.6.0 | High |
AIKIDO-2026-974181 adm-zip is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 0.6.0. | 0.6.0 - 0.6.0 | Medium |
AIKIDO-2026-652849 adm-zip is vulnerable to Interpretation Conflict in versions 0.0.1 - 0.6.0. | 0.0.1 - 0.6.0 | Medium |
AIKIDO-2026-482835 adm-zip is vulnerable to Denial of Service (DoS) in versions 0.1.3 - 0.6.0. | 0.1.3 - 0.6.0 | High |
AIKIDO-2026-272676 adm-zip is vulnerable to Denial of Service (DoS) in versions 0.5.14 - 0.6.0. | 0.5.14 - 0.6.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.