Implementation of JSON Web Signatures
78%
Total Score
63
100
94
75
50
The release has no build provenance attestation or trusted-publisher identity, reducing transparency about how the registry artifact was produced. The repository's release tooling and security scans provide some compensating project hygiene.
All recent repository commits came from one contributor, creating a concentrated maintenance risk. Organizational ownership provides some handoff capacity, but no second recent contributor is shown.
Only one commit was recorded in the last three months, with one active maintainer, indicating a slow recent maintenance pace despite the recent release history.
There are 20 open issues and 13 open pull requests, but no issues or pull requests were created or closed in the last month; this suggests limited recent responsiveness.
The repository has no security policy, leaving vulnerability-reporting and response expectations less transparent for a security-sensitive signing library.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-65945 jws is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 3.2.3 and 4.0.0 - 4.0.0. | 0.0.0 - 3.2.34.0.0 - 4.0.0 | High |
CVE-2016-1000223 jws is vulnerable to Security Vulnerability in versions 0.0.0 - 3.0.0. | 0.0.0 - 3.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
jwa Version ^2.0.1 | — | — |
safe-buffer Version ^5.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.