Package Health

node-jose

A JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers

Latest 2.2.0NPMNPM

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the measured three-month period. Combined with the stale release history, this is the strongest abandonment concern.

Build provenancecaution

No build provenance attestation or trusted-publisher identity is present. This weakens publication transparency, though it is not by itself evidence that the release is unsafe.

Dependency profilecaution

Nine runtime dependencies are declared, including cryptography-related and compatibility packages. This is a meaningful dependency surface but not excessive on its own.

Release historycaution

The package has 30 releases, but its latest release was published on February 16, 2023, with no releases in the last 12 months. That long gap materially raises maintenance and compatibility risk.

Repo issue activitycaution

There were no new or closed issues and no new or merged pull requests in the measured one-month period, with 63 open issues and 10 open pull requests. This indicates a backlog without visible recent triage.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-25653
node-jose is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 0.0.0 - 2.2.0.
0.0.0 - 2.2.0
High
CVE-2018-0114
node-jose is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 0.11.0.
0.0.0 - 0.11.0
High
CVE-2017-16007
node-jose is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 0.9.3.
0.0.0 - 0.9.3
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
long
Version ^5.2.0
—
—
pako
Version ^2.0.4
—
—
uuid
Version ^9.0.0
—
—
buffer
Version ^6.0.3
—
—
lodash
Version ^4.17.21
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
11 years ago
Unpacked Size
0.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform