fs-extra contains methods that aren't included in the vanilla Node.js fs package. Such as recursive mkdir, copy, and remove.
84%
Total Score
healthy
Healthy: active maintenance and a well-tested, licensed project outweigh minor workflow and type-declaration gaps.
The repository reports no build or security-scanning tools. This is a modest transparency and assurance gap, though active tests and commits partly compensate.
No repository security policy was found, leaving vulnerability reporting expectations unclear for a widely used library.
The package provides no type declarations, which makes TypeScript integration less convenient for this general-purpose library, but it does not indicate abandonment or unsafe maintenance.
The workflow audit completed cleanly and uses read-only permissions, but both analyzed action references are unpinned, making dependency changes less reproducible.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-57045 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. fs-extra is vulnerable to Improper Link Resolution Before File Access in versions 8.0.0 - 11.3.5. | 8.0.0 - 11.3.5 | Low |
| Dependency | Last Release | Score |
|---|---|---|
jsonfile Version ^6.0.1 | — | — |
graceful-fs Version ^4.2.0 | — | — |
universalify Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.