Low-Level OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
88%
Total Score
75
100
100
100
100
The repository is owned by the named individual panva rather than an organization, so there is no organization-level maintenance redundancy to offset contributor concentration.
All 24 commits in the last 3 months came from one contributor, creating meaningful continuity and bus-factor risk. The active release cadence and current repository activity partly offset this, but the concentration remains a caution.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10325 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. oauth4webapi is vulnerable to Cleartext Transmission of Sensitive Information in versions 0.0.1 - 2.17.0. | 0.0.1 - 2.17.0 | Medium |
AIKIDO-2024-10081 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. oauth4webapi is vulnerable to Authentication Bypass by Capture-replay in versions 2.8.0 - 2.8.0. | 2.8.0 - 2.8.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.