The project has clear documentation, tests, release notes, and a strong release cadence. Recent work is concentrated in one contributor, and all six workflow actions are unpinned; organization backing and build provenance reduce the concern.
79%
Total Score
63
100
100
75
100
All two recent commits came from one contributor, creating concentration risk; the organization-owned repository provides some capacity to hand maintenance off.
Only two commits were made in the last three months, so recent development is modest despite the recent release history.
There was one issue closure and two merged pull requests in the last month, but no new issues or pull requests, indicating limited recent interaction rather than clear abandonment.
No repository security policy was found, leaving vulnerability reporting expectations unclear.
The sole workflow was fully analyzed and scopes permissions at job level, with no untrusted checkouts or script injection. However, all six action references are unpinned; the reported cache-poisoning findings are low-confidence hygiene warnings and do not independently establish a severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-713161 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. h5wasm is vulnerable to Heap-based Buffer Overflow in versions 0.7.6 - 0.10.2. | 0.7.6 - 0.10.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.