Clear documentation and reproducible publishing support day-to-day use. The project relies on one recent contributor, and its workflows use 18 unpinned actions with broad write permissions, so pinning this version is sensible.
78%
Total Score
50
100
100
88
100
One contributor made 100% of the last three months' commits. With user-owned rather than organization-owned backing, this creates meaningful continuity risk despite recent activity.
Eight commits were made in the last three months, but all recent activity came from one active maintainer, limiting the depth of the maintenance base.
All five workflows were analyzed, but all 18 action references are unpinned and three workflows grant top-level write permissions. The audit also reports high-confidence bot-condition and template-injection hygiene findings; no untrusted checkout or script-injection sink was found, so this is caution rather than a severe standalone risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-988529 axios-cache-interceptor is vulnerable to Information Disclosure in versions 0.0.1 - 1.12.2. | 0.0.1 - 1.12.2 | Low |
CVE-2025-69202 axios-cache-interceptor is vulnerable to Use of Cache Containing Sensitive Information in versions 0.0.0 - 1.11.1. | 0.0.0 - 1.11.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
try Version ^1.0.3 | — | — |
http-vary Version ^1.0.3 | — | — |
fast-defer Version ^1.1.9 | — | — |
object-code Version ^2.0.0 | — | — |
cache-parser Version ^1.2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.