A full-featured HTTP proxy for Node.js.
87%
Total Score
100
100
89
75
50
No build attestation or trusted-publisher provenance is available, so consumers cannot independently verify how this artifact was produced.
The project uses TypeScript, Vitest, and npm scripts, but no security-scanning tools were detected in the repository.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.5.5 is not a prerelease and recent releases contain no prerelease versions, though the 0.x major version leaves more room for breaking changes than a 1.x release.
All three workflows were analyzed with no untrusted checkouts, script injection, or top-level write permissions, and all eight action references are pinned. Each workflow has a high-confidence low-severity adhoc-packages finding because it installs a package outside a lockfile.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-267343 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. httpxy is vulnerable to HTTP Request Smuggling in versions 0.5.0 - 0.5.4. | 0.5.0 - 0.5.4 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.