Healthy and suitable to depend on. It has a long, active release history, current repository activity, tests, documentation, security scanning, and build provenance; the main caveats are concentrated commit ownership and uneven GitHub Actions permission hardening.
88%
Total Score
88
100
100
60
100
All 12 workflows were analyzed with no pull-request-target or script-injection findings. One workflow checks out untrusted content and three use workflow_run, so CI boundaries still warrant review.
The package uses postinstall and prepare scripts, which add install-time execution and therefore some supply-chain exposure. The build provenance and extensive repository tooling provide partial reassurance, but do not remove that exposure.
One contributor made about 89% of the last three months' commits, creating concentration risk. A second contributor remained active and the repository is organization-owned, which partly mitigates handoff risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
Eleven of 12 workflows lack top-level token permissions, none declare read-only permissions, and one workflow has top-level write access. This is a meaningful CI privilege-hardening gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-862812 mediasoup is vulnerable to Authentication Bypass in versions 3.20.0 - 3.20.5. | 3.20.0 - 3.20.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
tar Version ^7.5.22 | — | — |
debug Version ^4.4.3 | — | — |
node-fetch Version ^3.3.2 | — | — |
flatbuffers Version ^25.9.23 | — | — |
supports-color Version ^11.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.