Package Health

box-node-sdk

Official SDK for Box Platform APIs

Latest 10.17.0NPMNPM

78%

Total Score

healthy

Healthy, with active releases and project backing offset by workflow hygiene issues and concentrated recent contributions.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the 31 recent commits. The Box organization provides backing, but no second active contributor is shown, leaving recent maintenance concentrated.

Security policycaution

The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting guidance unclear for a package with active maintenance.

Workflow auditcaution

All 8 workflows were analyzed and all 8 use read-only permissions, with no untrusted checkout or script-injection findings. However, all 15 action references are unpinned, and high-confidence template-injection and bot-condition findings remain workflow hygiene concerns.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10367 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
box-node-sdk is vulnerable to Observable Timing Discrepancy in versions 1.37.1 - 3.8.0.
1.37.1 - 3.8.0
Low

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
jose
Version ^5.2.2
—
—
uuid
Version ^11.1.1
—
—
tslib
Version ^2.6.2
—
—
buffer
Version ^6.0.3
—
—
form-data
Version ^4.0.4
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
10 years ago
Unpacked Size
26.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform