Package Health

janus-gateway

A javascript library for interacting with the C based Janus WebRTC Server

Latest 1.4.2NPMNPM

82%

Total Score

healthy

Healthy, with a license mismatch requiring clarification before adoption.

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The artifact includes a COPYING file identifying GPL-3.0, while the manifest declares MIT. Because the detected license is not covered by the declaration, this is a meaningful transparency and compliance concern.

Workflow auditcaution

The workflow audit was complete, found no untrusted checkout or script-injection paths, and observed read-only permissions. However, all 11 analyzed action references are unpinned, leaving avoidable build reproducibility and action-update risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10196 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
janus-gateway is vulnerable to Use after free in versions 0.0.1 - 1.3.3.
0.0.1 - 1.3.3
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
webrtc-adapter
Version 9.0.3
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
8 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform