Another JSON Schema Validator
78%
Total Score
83
100
100
75
50
No build attestation, trusted publisher identity, or staged-publishing evidence is present, leaving artifact provenance less transparent than it could be.
A prepublish lifecycle script is present, which adds build or publication-time execution behavior and warrants some review, although it is not reported as an install script.
The repository recorded zero commits and zero active maintainers in the last three months, a significant maintenance warning. Recent releases and a recent repository push partly offset the concern but do not remove it.
Neither workflow declares top-level token permissions, so the effective permissions are less explicit than ideal; however, neither workflow requests top-level write access.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-273849 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. ajv is vulnerable to Prototype Pollution in versions 3.0.0 - 6.14.0 and 7.0.0 - 8.18.0. | 3.0.0 - 6.14.07.0.0 - 8.18.0 | Low |
CVE-2025-69873 ajv is vulnerable to Uncontrolled Resource Consumption in versions 7.0.0-alpha.0 - 8.18.0 and 0.0.0 - 6.14.0. | 0.0.0 - 6.14.07.0.0-alpha.0 - 8.18.0 | Medium |
CVE-2020-15366 ajv is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in versions 0.0.0 - 6.12.3. | 0.0.0 - 6.12.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
fast-uri Version ^3.0.1 | — | — |
fast-deep-equal Version ^3.1.3 | — | — |
require-from-string Version ^2.0.2 | — | — |
json-schema-traverse Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.