ketcher-core 3.18.0 appears to be a healthy, actively maintained dependency. It has a long release history, frequent recent releases, a stable major version, current activity in a non-archived organization-owned repository, 27 active contributors, substantial commit and pull-request throughput, clear licensing, type declarations, tests in the artifact, and no install-time lifecycle scripts. The main concerns are absent build provenance, no security policy, and incomplete GitHub Actions permission declarations, but these are transparency and workflow-hygiene gaps rather than evidence of abandonment; the repository's active maintenance and security scanning provide meaningful compensation.
89%
Total Score
100
100
100
80
50
No build attestation, trusted publisher, or staged publishing is reported, limiting release reproducibility and publisher verification. This is a transparency caution, not a maintenance failure.
No repository security policy is present, reducing transparency around vulnerability reporting and response expectations.
Eight of nine workflows lack top-level permissions declarations, one workflow declares top-level write permissions, and none declare read-only permissions. This is a genuine workflow hardening gap, although the dangerous-workflow analysis found no directly unsafe patterns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-900777 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. ketcher-core is vulnerable to Cross-Site Scripting (XSS) in versions 2.23.0 - 3.16.0 and 3.17.0 - 3.17.0. | 2.23.0 - 3.16.03.17.0 - 3.17.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
d3 Version ^7.8.5 | — | — |
ajv Version ^8.10.0 | — | — |
dpdm Version ^4.2.0 | — | — |
paper Version ^0.12.18 | — | — |
assert Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.