DashClaw 5.33.9 appears to be a healthy, actively maintained dependency: it has a current non-deprecated stable release, npm provenance, an intact and recently updated repository, substantial recent commit activity from multiple contributors, repository tests and changelog coverage, security tooling, and a security policy. The main concerns are the single npm publishing account and incomplete explicit GitHub Actions permission declarations, including two workflows with top-level write permissions; these are meaningful hygiene and operational risks but do not outweigh the strong maintenance and transparency evidence. The package artifact is intentionally small and includes licensing, type declarations, and no install-time lifecycle scripts.
86%
Total Score
80
100
90
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-190281 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dashclaw is vulnerable to Authorization Bypass in versions 4.63.0 - 5.19.0. | 4.63.0 - 5.19.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.