Package Health

ghost

The professional publishing platform

Latest 6.69.0NPMNPM

88%

Total Score

healthy

Frequent releases, 51 active contributors, and strong project backing outweigh limited workflow and dependency-hygiene concerns.

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 171 runtime dependencies, creating a broad maintenance and transitive-update surface compared with a small library. Its application-sized package structure partly explains this profile but does not remove the added complexity.

Maintainerscaution

Publishing access is concentrated around the ghost.org domain and the repository is organization-backed, which supports continuity. Several consumer Gmail accounts and outside-domain accounts remain account-hygiene concerns: erisds, minimaluminium, bobvaneck, sagzy, vershwal, mike182uk, renatoworks, weylandswart, tmciesco, 9larsons, allouis, johnonolan, jloh, sam-lord, joeegrigg, and jonhickman.

Workflow auditcaution

All 25 workflows were analyzed and all 160 action references are pinned, with no untrusted checkout or script-injection findings. High-confidence findings include broad GitHub App permissions, template-injection patterns, and ad hoc package installs; low-confidence cache findings are hygiene concerns, while broad workflow write permissions add mild caution.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-105642 New
ghost is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 6.56.0 - 6.67.0.
6.56.0 - 6.67.0
High
CVE-2026-105643 New
ghost is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.34.0 - 6.67.0.
6.34.0 - 6.67.0
High
CVE-2026-105644 New
ghost is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 6.67.0.
4.0.0 - 6.67.0
Medium
CVE-2026-105645 New
ghost is vulnerable to Inefficient Regular Expression Complexity in versions 5.37.0 - 6.67.0.
5.37.0 - 6.67.0
Medium
CVE-2026-105646 New
ghost is vulnerable to Inefficient Regular Expression Complexity in versions 4.0.0 - 6.67.0.
4.0.0 - 6.67.0
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
got
Version 16.0.0
—
—
rss
Version 1.2.2
—
—
zod
Version 4.6.5
—
—
clsx
Version 2.1.1
—
—
cors
Version 2.8.6
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
14 years ago
Unpacked Size
52.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform