A JS implementation of JSONPath with some additional operators
72%
Total Score
caution
Recent releases and repository work offset an explicit maintenance warning; concentrated ownership and unpinned CI remain concerns.
No build attestation or trusted-publisher provenance is present, leaving publication origin less verifiable; the repository's build and security tooling provide partial compensation.
One contributor made 92.5% of the 40 recent commits; although the repository is organization-owned and two other contributors were active, maintenance remains highly concentrated.
The only workflow was fully analyzed with no injection or high-confidence audit findings, but all 3 action references are unpinned and the workflow has no top-level permissions block, creating moderate CI hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-1302 jsonpath-plus is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 10.3.0. | 0.0.0 - 10.3.0 | Critical |
AIKIDO-2025-10096 jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 10.2.0 - 10.2.0. | 10.2.0 - 10.2.0 | Critical |
AIKIDO-2024-10345 jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 0.1.0 - 10.1.0. | 0.1.0 - 10.1.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
jsep Version ^1.4.0 | — | — |
@jsep-plugin/regex Version ^1.0.4 | — | — |
@jsep-plugin/assignment Version ^1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.