This release appears suitable for dependency use, with strong evidence of active maintenance, rapid release activity, stable major-version status, a non-archived matching repository, npm provenance, and no install-time lifecycle scripts. The main concerns are that the project is young, nearly all recent commits come from one contributor, repository security scanning is absent, one workflow has top-level write permissions, and no security policy is published. Missing package tests, changelog, and type declarations are less significant here because the repository contains tests and a changelog and the package is primarily a command-line tool. Overall, it is usable but merits normal review of its workflow and release controls before adopting it in a high-trust build.
78%
Total Score
60
85
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-36897 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. adversarial-review is vulnerable to Command Injection in versions 1.1.0 - 2.9.1. | 1.1.0 - 2.9.1 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.