A super light and fast circular JSON parser.
86%
Total Score
70
100
100
90
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less independently verifiable than it could be.
Only one registry account has publish access. This is a real publishing continuity concern, although repository activity shows that the account is actively maintaining the project.
The repository is owned by a user rather than an organization, so the single-maintainer concentration is not offset by visible organizational handoff capacity.
All 7 recent commits came from one contributor, creating a concentrated maintenance dependency and increasing abandonment risk if that contributor becomes unavailable.
All three workflows lack top-level permission declarations, and none explicitly declares read-only permissions; although no top-level write access was observed, this weakens least-privilege clarity.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-33228 flatted is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in versions 0.0.0 - 3.4.1. | 0.0.0 - 3.4.1 | High |
CVE-2026-32141 flatted is vulnerable to Uncontrolled Recursion in versions 0.0.0 - 3.4.0. | 0.0.0 - 3.4.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.