A tiny (117 bytes), secure URL-friendly unique string ID generator
91%
Total Score
healthy
Active releases, verified publishing, and a maintained source repository make this a strong dependency.
The repository is owned by the identified user account ai rather than an organization. This does not negate the strong activity evidence, but it offers less formal organizational continuity.
One contributor made about 92% of the recent commits, creating concentration risk. However, three additional contributors were active during the same period, partly compensating for that risk.
The project uses Vite and TypeScript, but no security-scanning tool was detected. This is a modest repository-hygiene gap, not evidence of unsafe code by itself.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-73086 nanoid is vulnerable to Integer Overflow or Wraparound in versions 0.0.0 - 3.3.12 and 4.0.0 - 5.1.11. | 0.0.0 - 3.3.124.0.0 - 5.1.11 | High |
AIKIDO-2026-148507 nanoid is vulnerable to Denial of Service (DoS) in versions 3.1.9 - 3.3.17. | 3.1.9 - 3.3.17 | Medium |
AIKIDO-2026-690382 nanoid is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.1.15. | 0.0.1 - 5.1.15 | Medium |
AIKIDO-2026-712572 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. nanoid is vulnerable to Denial of Service (DoS) in versions 3.1.16 - 3.3.11 and 4.0.0 - 5.1.10. | 3.1.16 - 3.3.114.0.0 - 5.1.10 | Medium |
CVE-2024-55565 nanoid is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 4.0.0 - 5.0.9 and 0.0.0 - 3.3.8. | 0.0.0 - 3.3.84.0.0 - 5.0.9 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.