Lexes ES modules returning their import/export metadata
88%
Total Score
healthy
Healthy: frequent releases and active repository work support dependable maintenance.
The release has no build attestation or trusted-publisher provenance, leaving publication origin less independently verifiable despite the otherwise active project.
The repository is owned by an individual rather than an organization, so the concentrated contributor activity and single registry publisher are not supported by organizational handoff capacity.
The top contributor made about 65% of recent commits, but a second contributor made about 26% and three others contributed, making this a moderate rather than severe concentration risk.
The repository uses build tooling, including Babel, SWC, TypeScript, and npm scripts, but reports no security-scanning tools, leaving a modest verification gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-875097 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. es-module-lexer is vulnerable to Out-of-bounds Write in versions 0.3.0 - 2.3.2. | 0.3.0 - 2.3.2 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.