The most comprehensive authentication framework for TypeScript.
94%
Total Score
100
60
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-906996 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to User Enumeration in versions 1.3.7 - 1.6.25. | 1.3.7 - 1.6.25 | Medium |
AIKIDO-2026-204536 better-auth is vulnerable to Insecure Cryptographic Defaults in versions 0.0.1 - 1.6.10. | 0.0.1 - 1.6.10 | High |
AIKIDO-2026-379318 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.1.0 - 1.6.23. | 0.1.0 - 1.6.23 | Medium |
CVE-2026-53516 better-auth is vulnerable to Improper Authentication in versions 0.0.0 - 1.6.11. | 0.0.0 - 1.6.11 | High |
CVE-2026-53514 better-auth is vulnerable to Improper Authentication in versions 0.0.0 - 1.6.11. | 0.0.0 - 1.6.11 | High |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.3.6 | — | — |
defu Version ^6.1.4 | — | — |
jose Version ^6.2.3 | — | — |
kysely Version ^0.28.17 || ^0.29.0 | — | — |
nanostores Version ^1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.