Healthy and suitable to use. It has a long release history, regular recent releases, an active matching repository, and clear licensing; the main caveats are that recent work comes from one contributor and the workflow lacks explicit token permissions.
86%
Total Score
75
100
90
90
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10412 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. file-type is vulnerable to Denial of Service (DoS) in versions 17.0.0 - 21.3.2. | 17.0.0 - 21.3.2 | Medium |
CVE-2026-32630 file-type is vulnerable to Uncontrolled Resource Consumption in versions 20.0.0 - 21.3.1. | 20.0.0 - 21.3.1 | Medium |
CVE-2026-31808 file-type is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 13.0.0 - 21.3.1. | 13.0.0 - 21.3.1 | Medium |
CVE-2022-36313 file-type is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 17.0.0 - 17.1.3 and 13.0.0 - 16.5.4. | 13.0.0 - 16.5.417.0.0 - 17.1.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
strtok3 Version ^10.3.5 | — | — |
token-types Version ^6.1.2 | — | — |
uint8array-extras Version ^1.5.0 | — | — |
@tokenizer/inflate Version ^0.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.