A robust, performance-focused and full-featured Redis client for Node.js.
92%
Total Score
100
100
95
90
50
No registry build attestation or trusted-publisher provenance is available, leaving the connection between the published artifact and its source build less transparent; the active matching repository partly compensates.
The project uses TypeScript and npm build tooling, but no security scanning tools were detected. The repository's security policy and clean workflow analysis provide partial compensating evidence, so this is a modest hygiene gap.
None of the six workflows declares top-level token permissions, so least-privilege intent is not explicit; however, no workflow declares top-level write access, limiting the observed concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-538318 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. ioredis is vulnerable to Prototype Pollution in versions 2.0.0 - 5.11.1. | 2.0.0 - 5.11.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
debug Version 4.4.3 | — | — |
denque Version 2.1.0 | — | — |
redis-errors Version 1.2.0 | — | — |
cluster-key-slot Version 1.1.1 | — | — |
@ioredis/commands Version 2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.