i18next-http-backend is a backend layer for i18next using in Node.js, in the browser and for Deno.
88%
Total Score
90
100
94
90
50
No build attestation, trusted publisher identity, or staged publishing was observed, leaving release-origin assurance weaker than it could be.
All six recent commits came from one contributor with a 100% share, creating contributor-concentration risk; the organization-owned repository partially compensates by providing potential maintenance handoff capacity.
TypeScript build tooling is present, but no repository security-scanning tool was detected, leaving a security-hygiene gap.
Both workflows lack top-level token-permission declarations, so least-privilege CI permissions are not explicitly established; neither workflow declares top-level write access.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-105800 New i18next-http-backend is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 4.0.2. | 0.0.0 - 4.0.2 | Low |
CVE-2026-41691 i18next-http-backend is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 3.0.5. | 0.0.0 - 3.0.5 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.