JSON.parse with bigints support
58%
Total Score
33
80
88
The package has 17 releases over roughly 13 years, but none in the last 12 months and the latest release was about 6 years ago. This materially raises maintenance and compatibility risk.
The repository had zero commits and zero active maintainers in the last three months. Combined with the old registry release, this is strong evidence of inactive maintenance.
The repository is owned by an individual rather than an organization, so there is no observed organizational backing to compensate for the thin maintainer base or recent inactivity.
There are 32 open issues and 26 open pull requests, with no issues or pull requests opened or merged in the last month. The backlog and inactivity indicate limited current maintenance capacity.
No build tooling or security scanning tools were detected. For this small, directly published JavaScript library the missing build layer is not inherently concerning, but the lack of security scanning is a minor hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-8237 json-bigint is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 1.0.0. | 0.0.0 - 1.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
bignumber.js Version ^9.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.