Official Box TypeScript Generated SDK
15%
Total Score
63
100
80
75
50
The package has 44 releases over about three years with a prior median interval of about 15 days, but it has had no release in the last 12 months, indicating a severe recent slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, confirming the absence of current maintenance.
The linked repository is archived, making ongoing fixes and maintenance unlikely even though it was pushed recently. An archived source repository is a severe dependency and abandonment risk.
No build attestation or trusted-publisher provenance is present, reducing release transparency. This is a supply-chain hygiene gap, not evidence that the package is malicious.
There are no open issues and seven open pull requests, but no issues or pull requests were merged in the last month, consistent with limited current activity.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10370 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. box-typescript-sdk-gen is vulnerable to Observable Timing Discrepancy in versions 0.1.0 - 1.15.1. | 0.1.0 - 1.15.1 | Low |
| Dependency | Last Release | Score |
|---|---|---|
jose Version ^5.2.2 | — | — |
uuid Version ^9.0.0 | — | — |
tslib Version ^2.6.2 | — | — |
buffer Version ^6.0.3 | — | — |
form-data Version ^4.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.