Memory compression system for Claude Code - persist context across sessions
83%
Total Score
healthy
Frequent releases and strong repository activity outweigh workflow pinning and publishing-hygiene concerns.
The repository is owned by a named individual rather than an organization, so continuity depends on a narrower ownership base. This is partly offset by the repository's very strong recent release and contribution activity.
The project uses TypeScript, npm scripts, esbuild, and tsup, showing an established build process. No security scanning tools were detected, which is a modest transparency and hygiene gap.
All 8 workflows were analyzed with no untrusted checkouts or script injection, and four scope permissions at job level. However, all 36 action references are unpinned, and the high-confidence trusted-publishing finding indicates registry publishing uses a long-lived token; the low-confidence cache findings are hygiene concerns only.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-11330 claude-mem is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.0.0 - 12.0.0. | 0.0.0 - 12.0.0 | Low |
AIKIDO-2026-10620 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. claude-mem is vulnerable to Authentication Bypass in versions 1.0.0 - 12.3.2. | 1.0.0 - 12.3.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
better-auth Version ^1.6.16 | — | — |
@better-auth/api-key Version ^1.6.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.