Hierarchical node.js configuration with files, environment variables, command-line arguments, and atomic object merging.
64%
Total Score
50
100
89
67
50
No build attestation, trusted publisher, or staged publishing is present, leaving release provenance less transparent than it could be.
The project is mature, with 59 releases since 2011, but it had no releases in the last 12 months and the latest release was in April 2025, which lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last 3 months, a meaningful sign of slowing maintenance and possible abandonment.
The repository has 98 open issues and 15 open pull requests, with no issues or pull requests closed in the last month, suggesting limited recent triage capacity.
The repository reports no build tooling and no security scanning tools. This is a hygiene gap, though it is not severe enough to make the release unfit on its own.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-21803 nconf is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 0.11.4. | 0.0.0 - 0.11.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
ini Version ^2.0.0 | — | — |
async Version ^3.0.0 | — | — |
yargs Version ^16.1.1 | — | — |
secure-keys Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.