Canvas graphics API backed by Cairo
78%
Total Score
100
88
67
50
No build attestation or staged publishing is reported, so consumers have limited verifiable evidence about how the release artifact was produced.
The artifact contains a license file, but it is detected as Unlicense while the manifest declares MIT. That mismatch creates avoidable legal and transparency uncertainty.
The project uses build tooling but reports no security-scanning tools. That is a modest transparency gap rather than evidence of abandonment.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear for a widely used native package.
Both workflows were analyzed without untrusted checkouts or script-injection findings, but all 16 action references are unpinned and one workflow grants top-level write permissions. These are workflow hygiene concerns, not a severe risk here.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10522 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. canvas is vulnerable to Use-After-Free in versions 2.0.0 - 2.11.2. | 2.0.0 - 2.11.2 | Low |
CVE-2020-8215 canvas is vulnerable to Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in versions 0.0.0 - 1.6.11. | 0.0.0 - 1.6.11 | High |
| Dependency | Last Release | Score |
|---|---|---|
node-addon-api Version ^7.0.0 | — | — |
prebuild-install Version ^7.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.