Ultra-fast MessagePack implementation with extensions for records and structured cloning
87%
Total Score
75
100
100
75
50
No build attestation or trusted-publisher provenance is available. This limits publication transparency, but the active release and repository history provide compensating maintenance evidence.
A prepare install-time script is present, so installation performs additional project-defined work beyond unpacking files. This is a modest transparency and supply-chain concern, without evidence here that the script is harmful.
The repository is owned by an individual rather than an organization, so there is no organizational handoff signal to offset the concentrated contributor base. Active maintenance still provides meaningful support.
Two contributors were active in the last three months, but the leading contributor made 80% of commits. The second contributor provides some continuity, though maintenance remains concentrated.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-52079 msgpackr is vulnerable to Uncontrolled Recursion in versions 0.0.0 - 1.10.1. | 0.0.0 - 1.10.1 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.