The professional publishing platform
88%
Total Score
healthy
Frequent releases, 51 active contributors, and strong project backing outweigh limited workflow and dependency-hygiene concerns.
The package declares 171 runtime dependencies, creating a broad maintenance and transitive-update surface compared with a small library. Its application-sized package structure partly explains this profile but does not remove the added complexity.
Publishing access is concentrated around the ghost.org domain and the repository is organization-backed, which supports continuity. Several consumer Gmail accounts and outside-domain accounts remain account-hygiene concerns: erisds, minimaluminium, bobvaneck, sagzy, vershwal, mike182uk, renatoworks, weylandswart, tmciesco, 9larsons, allouis, johnonolan, jloh, sam-lord, joeegrigg, and jonhickman.
All 25 workflows were analyzed and all 160 action references are pinned, with no untrusted checkout or script-injection findings. High-confidence findings include broad GitHub App permissions, template-injection patterns, and ad hoc package installs; low-confidence cache findings are hygiene concerns, while broad workflow write permissions add mild caution.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-105642 New ghost is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 6.56.0 - 6.67.0. | 6.56.0 - 6.67.0 | High |
CVE-2026-105643 New ghost is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.34.0 - 6.67.0. | 6.34.0 - 6.67.0 | High |
CVE-2026-105644 New ghost is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 6.67.0. | 4.0.0 - 6.67.0 | Medium |
CVE-2026-105645 New ghost is vulnerable to Inefficient Regular Expression Complexity in versions 5.37.0 - 6.67.0. | 5.37.0 - 6.67.0 | Medium |
CVE-2026-105646 New ghost is vulnerable to Inefficient Regular Expression Complexity in versions 4.0.0 - 6.67.0. | 4.0.0 - 6.67.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
got Version 16.0.0 | — | — |
rss Version 1.2.2 | — | — |
zod Version 4.6.5 | — | — |
clsx Version 2.1.1 | — | — |
cors Version 2.8.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.