Package Health

import-in-the-middle

Intercept imports in Node.js

Latest 3.5.2NPMNPM

92%

Total Score

healthy

Healthy release with active Node.js project backing, frequent releases, and verified publishing; only minor workflow hygiene concerns.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The project uses TypeScript, npm scripts, and Babel, but no security-scanning tools were detected. This is a modest transparency gap, not evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed successfully, use no unpinned actions, and contain no untrusted checkouts or script injection. A high-confidence low-severity finding shows the release workflow installs a package outside a lockfile, creating a minor hygiene concern.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-38704
import-in-the-middle is vulnerable to Improper Input Validation in versions 0.0.0 - 1.4.1.
0.0.0 - 1.4.1
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
es-module-lexer
Version ^3.0.2
—
—
cjs-module-lexer
Version ^2.2.0
—
—
module-details-from-path
Version ^1.0.4
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
5 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform