Package Health

claude-mem

Memory compression system for Claude Code - persist context across sessions

Latest 13.35.0NPMNPM

83%

Total Score

healthy

Frequent releases and strong repository activity outweigh workflow pinning and publishing-hygiene concerns.

Are you affected? Scan for Free

Health Score Breakdown

Project backingcaution

The repository is owned by a named individual rather than an organization, so continuity depends on a narrower ownership base. This is partly offset by the repository's very strong recent release and contribution activity.

Repo toolingcaution

The project uses TypeScript, npm scripts, esbuild, and tsup, showing an established build process. No security scanning tools were detected, which is a modest transparency and hygiene gap.

Workflow auditcaution

All 8 workflows were analyzed with no untrusted checkouts or script injection, and four scope permissions at job level. However, all 36 action references are unpinned, and the high-confidence trusted-publishing finding indicates registry publishing uses a long-lived token; the low-confidence cache findings are hygiene concerns only.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-11330
claude-mem is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.0.0 - 12.0.0.
0.0.0 - 12.0.0
Low
AIKIDO-2026-10620 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
claude-mem is vulnerable to Authentication Bypass in versions 1.0.0 - 12.3.2.
1.0.0 - 12.3.2
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
better-auth
Version ^1.6.16
—
—
@better-auth/api-key
Version ^1.6.16
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
1 year ago
Unpacked Size
19.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform