Package Health

jsonpath-plus

A JS implementation of JSONPath with some additional operators

Latest 11.2.0NPMNPM

72%

Total Score

caution

Recent releases and repository work offset an explicit maintenance warning; concentrated ownership and unpinned CI remain concerns.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is present, leaving publication origin less verifiable; the repository's build and security tooling provide partial compensation.

Repo bus factorcaution

One contributor made 92.5% of the 40 recent commits; although the repository is organization-owned and two other contributors were active, maintenance remains highly concentrated.

Workflow auditcaution

The only workflow was fully analyzed with no injection or high-confidence audit findings, but all 3 action references are unpinned and the workflow has no top-level permissions block, creating moderate CI hygiene concerns.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-1302
jsonpath-plus is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 10.3.0.
0.0.0 - 10.3.0
Critical
AIKIDO-2025-10096
jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 10.2.0 - 10.2.0.
10.2.0 - 10.2.0
Critical
AIKIDO-2024-10345
jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 0.1.0 - 10.1.0.
0.1.0 - 10.1.0
Critical

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
jsep
Version ^1.4.0
—
—
@jsep-plugin/regex
Version ^1.0.4
—
—
@jsep-plugin/assignment
Version ^1.3.0
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
10 years ago
Unpacked Size
0.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform