Lightweight debugging utility for Node.js and the browser
68%
Total Score
67
100
89
90
50
No build attestation or trusted-publisher provenance is available, reducing publication transparency, although this is not by itself evidence that the release is unsafe.
The project is mature, with 78 releases over roughly 15 years, but it has had no registry releases in the last 12 months, indicating a quiet release cadence.
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful maintenance concern, though the long release history and recent push provide some compensating evidence.
There were no new or closed issues in the last month and no merged pull requests, while three pull requests were opened; this suggests limited recent project throughput.
The repository reports no build tooling or security scanning, leaving automated quality and security checks unclear for a package with a broad consumer base.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-59144 debug is vulnerable to Embedded Malicious Code in versions 4.4.2 - 4.4.2. | 4.4.2 - 4.4.2 | High |
CVE-2017-20165 debug is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 2.6.9 and 3.0.0 - 3.1.0. | 0.0.0 - 2.6.93.0.0 - 3.1.0 | High |
CVE-2017-16137 debug is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 2.6.9, 3.0.0 - 3.1.0, 3.2.0 - 3.2.7 and 4.0.0 - 4.3.1. | 0.0.0 - 2.6.93.0.0 - 3.1.03.2.0 - 3.2.7 +1 more | Low |
| Dependency | Last Release | Score |
|---|---|---|
ms Version ^2.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.