Offers a async require.resolve function. It's highly configurable.
92%
Total Score
healthy
Healthy release with active maintenance, clear provenance, and a well-supported source repository.
A prepare script runs during installation, adding some install-time behavior, but this is moderated by the package's build tooling and provenance evidence.
All five workflows were analyzed with no untrusted checkouts, script injection, or unpinned actions. High-confidence findings report spoofable bot conditions and blanket app-token permissions in Dependabot, while adhoc package installs are lower-severity hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-549562 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. enhanced-resolve is vulnerable to Path Traversal in versions 4.2.0 - 5.24.3. | 4.2.0 - 5.24.3 | Low |
AIKIDO-2026-11084 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. enhanced-resolve is vulnerable to Path Traversal in versions 4.2.0 - 5.22.0. | 4.2.0 - 5.22.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
tapable Version ^2.3.3 | — | — |
graceful-fs Version ^4.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.