JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.
68%
Total Score
67
93
90
50
No build attestation, trusted publisher identity, or staged publishing is reported, leaving the correspondence between source and published artifact less verifiable.
A prepublish lifecycle script is present, adding some publishing-process complexity and supply-chain exposure. The signal does not show an install-time script, so this is a caution rather than a severe dependency risk.
There were zero commits and zero active maintainers in the last three months, a significant sign that day-to-day maintenance may have slowed. The recent registry release and repository push provide some compensating evidence but do not remove the concern.
The repository has 403 open issues and 61 open pull requests, while no issues were closed or pull requests merged in the last month. This backlog suggests limited responsiveness despite some incoming activity.
The repository uses build tooling, but no security scanning tools were detected. For a cryptography library, the absence of visible automated security scanning is a meaningful maintenance and transparency gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-85393 node-forge is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | High |
CVE-2026-33896 node-forge is vulnerable to Improper Certificate Validation in versions 0.0.0 - 1.3.3. | 0.0.0 - 1.3.3 | High |
CVE-2026-33895 node-forge is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | High |
CVE-2026-33894 node-forge is vulnerable to Improper Input Validation in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | High |
CVE-2026-33891 node-forge is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.