The Sodium cryptographic library compiled to pure JavaScript (wrappers)
88%
Total Score
75
100
100
67
50
No build attestation or trusted-publisher provenance is present, leaving the origin of the published artifact less independently verifiable.
Only one registry account has publish access, which is a modest operational concentration risk, though repository activity shows a second active contributor.
The repository has no published security policy, reducing transparency about vulnerability reporting and response procedures.
The single workflow was fully analyzed with no audit findings or untrusted execution paths, and it scopes permissions at job level. Its one action reference is unpinned, a limited reproducibility and action-integrity weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
libsodium Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.