Package Health

adm-zip

Javascript implementation of zip for nodejs with support for electron original-fs. Allows user to create or extract zip files both in memory or to/from disk

Latest 0.6.1NPMNPM

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build provenance attestation or trusted-publisher identity is present, leaving release origin less independently verifiable.

Maintainerscaution

Only one registry account has publish access, creating some publishing continuity and account-compromise risk, although repository activity shows the project is actively maintained.

Project backingcaution

The repository is owned by an individual rather than an organization, so long-term continuity depends on a relatively narrow project base; this is partly offset by recent release and repository activity.

Token permissionscaution

All three workflows lack top-level permissions declarations, which weakens least-privilege clarity; none declares top-level write access, limiting the observed risk.

Version stabilitycaution

Version 0.6.1 is not a stable-major release, which is a modest compatibility concern, but it is not a prerelease and recent prerelease usage is absent.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-102282
adm-zip is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.0.0 - 0.6.0.
0.0.0 - 0.6.0
High
AIKIDO-2026-974181
adm-zip is vulnerable to Denial of Service (DoS) in versions 0.6.0 - 0.6.0.
0.6.0 - 0.6.0
Medium
AIKIDO-2026-652849
adm-zip is vulnerable to Interpretation Conflict in versions 0.0.1 - 0.6.0.
0.0.1 - 0.6.0
Medium
AIKIDO-2026-482835
adm-zip is vulnerable to Denial of Service (DoS) in versions 0.1.3 - 0.6.0.
0.1.3 - 0.6.0
High
AIKIDO-2026-272676
adm-zip is vulnerable to Denial of Service (DoS) in versions 0.5.14 - 0.6.0.
0.5.14 - 0.6.0
High

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
14 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform