Recursively merge values in a javascript object.
55%
Total Score
50
100
88
75
There were zero commits and zero active maintainers in the last three months, a strong indication that active maintenance has stopped or become sporadic.
The package has 16 releases over roughly 12 years, but none in the last five years, indicating substantially reduced maintenance activity.
There were no new or closed issues or pull requests in the last month, alongside seven open pull requests and ten open issues, suggesting limited ongoing triage.
The repository uses a build tool but reports no security scanning tools. For this small JavaScript utility, the missing scanning is a modest hygiene gap rather than a decisive risk.
The repository has no security policy. This is a transparency and response-process gap, though it is less severe than the demonstrated maintenance slowdown.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-26707 merge-deep is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 3.0.3. | 0.0.0 - 3.0.3 | Critical |
CVE-2018-3722 merge-deep is vulnerable to Modification of Assumed-Immutable Data (MAID) in versions 0.0.0 - 3.0.1. | 0.0.0 - 3.0.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
kind-of Version ^3.0.2 | — | — |
arr-union Version ^3.1.0 | — | — |
clone-deep Version ^0.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.