Node.js library for parsing crontab instructions
84%
Total Score
healthy
Active, established releases and a maintained repository outweigh concentrated ownership and unpinned workflow actions.
A prepare install-time script is present, adding some installation complexity, but this signal alone does not indicate a maintenance or abandonment problem.
Six contributors were active recently, but the top contributor made 80% of commits, leaving maintenance substantially concentrated despite some contributor breadth.
The project uses TypeScript and npm build tooling, but no security-scanning tools were detected, leaving a modest security-process transparency gap.
All five workflows were analyzed with no audit findings or untrusted checkouts, but all 16 action references are unpinned and three workflows grant top-level write permissions; these are workflow hygiene concerns, not severe evidence on their own.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-140382 New cron-parser is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.10.0. | 0.0.1 - 5.10.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
luxon Version ^3.7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.