HTTP proxying for the masses
60%
Total Score
67
100
89
75
50
No build attestation or trusted-publisher provenance was recorded, reducing publication transparency; this is a limitation rather than evidence that the release is unsafe.
The package has a long history and 103 releases, but its latest release was over six years ago and there were no releases in the last 12 months, indicating stale maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, so current maintenance capacity is not evident.
Issue and pull request activity is limited, with one new and one closed issue plus one new pull request in the last month and no merged pull requests; this provides little evidence of active development.
No build tooling or security scanning tools were detected, which weakens automated maintenance and security hygiene for a network-facing library.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-16014 http-proxy is vulnerable to Improper Check or Handling of Exceptional Conditions in versions 0.0.0 - 0.6.6. | 0.0.0 - 0.6.6 | High |
| Dependency | Last Release | Score |
|---|---|---|
eventemitter3 Version ^4.0.0 | — | — |
requires-port Version ^1.0.0 | — | — |
follow-redirects Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.