HTTP request logger middleware for node.js
95%
Total Score
100
100
95
100
100
No type declarations are provided, which is a minor consumer-ergonomics gap for TypeScript users, but it does not by itself indicate abandonment or poor supply-chain health.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-300232 morgan is vulnerable to Log Injection in versions 0.0.1 - 1.12.0. | 0.0.1 - 1.12.0 | Medium |
AIKIDO-2026-442728 morgan is vulnerable to Log Injection in versions 0.0.1 - 1.11.0. | 0.0.1 - 1.11.0 | Medium |
CVE-2026-5078 morgan is vulnerable to Improper Output Neutralization for Logs in versions 1.2.0 - 1.10.1. | 1.2.0 - 1.10.1 | Medium |
CVE-2019-5413 morgan is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.9.1. | 0.0.0 - 1.9.1 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
depd Version ~2.0.0 | — | — |
debug Version 2.6.9 | — | — |
basic-auth Version ~2.0.1 | — | — |
on-headers Version ~1.1.0 | — | — |
on-finished Version ~2.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.