Healthy and suitable to depend on, with routine maintenance-mode caveats. It has a long release history, recent releases and commits, strong repository documentation, and build provenance; the main concerns are a single registry maintainer and limited repository security controls.
82%
Total Score
80
100
95
80
100
Only one account has registry publish access, creating some publishing continuity risk. However, repository activity shows three active contributors, partly compensating for the narrow registry maintainer list.
The repository is owned by a user account rather than an organization, so the single registry maintainer and small contributor base are not supported by visible organizational backing.
The repository uses build tooling, but no security scanning tools were detected. For a native package this is a meaningful security-hygiene gap, though it does not by itself indicate abandonment or maliciousness.
The repository has no security policy. That weakens vulnerability-reporting transparency for a library that executes native code, although the active repository and other provenance signals provide some compensation.
Neither workflow declares top-level token permissions, and no workflow is explicitly read-only. Although no write permissions were detected, the lack of least-privilege declarations is a workflow hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-907567 isolated-vm is vulnerable to Type Confusion in versions 0.0.1 - 6.1.2 and 7.0.0 - 7.0.0. | 0.0.1 - 6.1.27.0.0 - 7.0.0 | Critical |
CVE-2022-39266 isolated-vm is vulnerable to Improper Input Validation in versions 0.0.0 - 4.3.6. | 0.0.0 - 4.3.6 | Critical |
CVE-2021-21413 isolated-vm is vulnerable to Improper Control of Dynamically-Managed Code Resources in versions 0.0.0 - 4.0.0. | 0.0.0 - 4.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
node-gyp-build Version ^4.8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.