Package Health

cron-parser

Node.js library for parsing crontab instructions

Latest 5.10.2NPMNPM

84%

Total Score

healthy

Active, established releases and a maintained repository outweigh concentrated ownership and unpinned workflow actions.

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

A prepare install-time script is present, adding some installation complexity, but this signal alone does not indicate a maintenance or abandonment problem.

Repo bus factorcaution

Six contributors were active recently, but the top contributor made 80% of commits, leaving maintenance substantially concentrated despite some contributor breadth.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no security-scanning tools were detected, leaving a modest security-process transparency gap.

Workflow auditcaution

All five workflows were analyzed with no audit findings or untrusted checkouts, but all 16 action references are unpinned and three workflows grant top-level write permissions; these are workflow hygiene concerns, not severe evidence on their own.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-140382 New
cron-parser is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.10.0.
0.0.1 - 5.10.0
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
luxon
Version ^3.7.2
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
13 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform