Auth0 Node.js SDK for the Management API v2.
91%
Total Score
healthy
A mature, actively maintained SDK with strong provenance and documentation, tempered by workflow pinning gaps.
A prepare install-time script is present, which adds a small amount of installation complexity, but the repository and package otherwise show mature build practices.
All five workflows were analyzed with no untrusted checkouts or script injection; however, 16 of 17 action references are unpinned and a high-confidence audit found an ad hoc package installation, leaving release hygiene as a caution.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-15125 auth0 is vulnerable to Generation of Error Message Containing Sensitive Information in versions 0.0.0 - 2.27.1. | 0.0.0 - 2.27.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
jose Version ^5.0.0 | — | — |
uuid Version ^11.1.1 | — | — |
auth0-legacy Version npm:auth0@^4.37.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.