Package Health

node-forge

JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.

Latest 1.4.0NPMNPM

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation, trusted publisher identity, or staged publishing is reported, leaving the correspondence between source and published artifact less verifiable.

Lifecycle scriptscaution

A prepublish lifecycle script is present, adding some publishing-process complexity and supply-chain exposure. The signal does not show an install-time script, so this is a caution rather than a severe dependency risk.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, a significant sign that day-to-day maintenance may have slowed. The recent registry release and repository push provide some compensating evidence but do not remove the concern.

Repo issue activitycaution

The repository has 403 open issues and 61 open pull requests, while no issues were closed or pull requests merged in the last month. This backlog suggests limited responsiveness despite some incoming activity.

Repo toolingcaution

The repository uses build tooling, but no security scanning tools were detected. For a cryptography library, the absence of visible automated security scanning is a meaningful maintenance and transparency gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-85393
node-forge is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 1.4.0.
0.0.0 - 1.4.0
High
CVE-2026-33896
node-forge is vulnerable to Improper Certificate Validation in versions 0.0.0 - 1.3.3.
0.0.0 - 1.3.3
High
CVE-2026-33895
node-forge is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 1.4.0.
0.0.0 - 1.4.0
High
CVE-2026-33894
node-forge is vulnerable to Improper Input Validation in versions 0.0.0 - 1.4.0.
0.0.0 - 1.4.0
High
CVE-2026-33891
node-forge is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 0.0.0 - 1.4.0.
0.0.0 - 1.4.0
High

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 months ago
Created
13 years ago
Unpacked Size
1.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform