Repair broken JSON documents
85%
Total Score
67
100
94
50
50
No build attestation or trusted-publisher provenance is present, leaving the relationship between source and published artifact less independently verifiable.
A prepare lifecycle script runs during installation or package preparation, adding execution during the install path; the available signals do not show what the script does.
The repository is owned by an individual rather than an organization, so the concentrated maintainer activity represents a genuine continuity risk rather than normal organizational delegation.
Three contributors were active, but the top contributor made 7 of 9 commits, or about 78%, leaving maintenance materially concentrated.
The project uses TypeScript, Babel, npm scripts, and Rollup for builds, but no security scanning tools were detected, leaving a security-process gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10058 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. jsonrepair is vulnerable to Improper Input Validation in versions 3.9.0 - 3.13.1. | 3.9.0 - 3.13.1 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.