Package Health

astro

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Latest 7.3.8NPMNPM

94%

Total Score

healthy

Active, organization-backed maintenance with strong release and contributor activity; only workflow hygiene keeps this from a top score.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

All 21 workflows were analyzed, all 75 action references are pinned, and no untrusted checkout or script-injection sink was found. However, high-confidence template injection and medium-confidence secrets inheritance were reported, creating a limited CI hygiene concern.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-84376
astro is vulnerable to Partial String Comparison in versions 0.0.0 - 7.2.3.
0.0.0 - 7.2.3
Medium
AIKIDO-2026-219768 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
astro is vulnerable to Authorization Bypass in versions 6.4.4 - 7.1.0.
6.4.4 - 7.1.0
Medium
CVE-2026-59729
astro is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 7.0.6.
0.0.0 - 7.0.6
Medium
CVE-2026-59727
astro is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.10.0 - 7.0.4.
3.10.0 - 7.0.4
Low
CVE-2026-73423
astro is vulnerable to Cross-Site Request Forgery (CSRF) in versions 7.0.0 - 7.0.6.
7.0.0 - 7.0.6
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
zod
Version ^4.6.5
—
—
clsx
Version ^2.1.1
—
—
diff
Version ^9.0.0
—
—
dset
Version ^3.1.4
—
—
obug
Version ^3.0.0
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
5 years ago
Unpacked Size
3.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform