FTP client for Node.js, supports FTPS over TLS, IPv6, Async/Await, and Typescript.
82%
Total Score
healthy
Frequent releases and an active repository offset a single-maintainer bus factor and weak build and workflow provenance.
No build attestation or trusted-publisher provenance is present, so consumers cannot independently verify how the published artifact was produced.
The package defines a prepare lifecycle script, which runs package-manager-controlled code during installation or preparation and adds some supply-chain exposure. No other lifecycle-script evidence was provided to show whether this is necessary or benign.
All 12 recent commits came from one contributor, creating a meaningful continuity risk despite the project's active history.
The project uses TypeScript for its build, but no repository security-scanning tools were detected. The missing scanning is a modest transparency gap, not evidence of unsafe code.
Both workflows were analyzed successfully with no injection, untrusted-checkout, or high-severity findings, and permissions are scoped or read-only. However, all four referenced actions are unpinned, leaving workflow behavior exposed to upstream action changes.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-221764 New basic-ftp is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.0.1 - 6.2.1. | 0.0.1 - 6.2.1 | Medium |
AIKIDO-2026-424618 basic-ftp is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.0.1 - 6.2.0. | 0.0.1 - 6.2.0 | High |
AIKIDO-2026-10909 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. basic-ftp is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 5.3.1. | 0.0.1 - 5.3.1 | High |
AIKIDO-2026-10643 basic-ftp is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.3.0. | 0.0.1 - 5.3.0 | High |
CVE-2026-41324 basic-ftp is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 5.2.2. | 0.0.0 - 5.2.2 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.