i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem.
84%
Total Score
90
100
94
90
50
No build attestation, trusted publisher identity, or staged publishing is present, leaving release provenance less independently verifiable.
All four recent commits came from one contributor, creating concentration risk. Organization ownership partially compensates because maintenance can potentially be handed off, but no second recent contributor is shown.
The repository uses TypeScript and Babel build tooling, but no security scanning tools are configured, leaving a security-hygiene gap.
Neither workflow declares top-level token permissions, and neither explicitly declares read-only permissions. Although no write permissions are observed, the lack of explicit least-privilege declarations is a workflow-hardening gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10994 i18next-fs-backend is vulnerable to Prototype Pollution in versions 0.0.1 - 2.6.5. | 0.0.1 - 2.6.5 | Critical |
CVE-2026-41693 i18next-fs-backend is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 2.6.4. | 0.0.0 - 2.6.4 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.