Enlightened OG Image generation for Nuxt.
86%
Total Score
healthy
Healthy: frequent releases and an active source project outweigh the concentrated contributor activity.
One contributor made 96% of the 75 recent commits, leaving continuity heavily dependent on that maintainer. The organization-owned repository provides some handoff capacity, but the concentration remains a caution.
The project uses TypeScript, Vitest, Vite, unbuild, and npm scripts, showing a structured build and test setup. No security scanning tool was detected, which is a modest transparency gap.
The repository has no security policy. This does not show unsafe code, but it leaves vulnerability-reporting expectations undocumented.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-61793 nuxt-og-image is vulnerable to Improper Input Validation in versions 6.0.2 - 6.7.0. | 6.0.2 - 6.7.0 | Medium |
AIKIDO-2026-10732 nuxt-og-image is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.2.5 - 6.4.8. | 6.2.5 - 6.4.8 | Low |
CVE-2026-34405 nuxt-og-image is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 6.2.5. | 0.0.0 - 6.2.5 | Medium |
CVE-2026-34404 nuxt-og-image is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 6.2.5. | 0.0.0 - 6.2.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ufo Version ^1.6.4 | — | — |
defu Version ^6.1.7 | — | — |
nypm Version ^0.6.10 | — | — |
ohash Version ^2.0.12 | — | — |
pathe Version ^2.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.