The official TypeScript library for the OpenAI API
94%
Total Score
healthy
Frequent releases, active maintenance, provenance, and strong repository controls outweigh concentrated contribution activity.
Eighteen of 19 publishing accounts use the openai.com domain, indicating coherent organization-controlled publishing. One consumer-domain account, aibrahim-openai (gmail.com), is a minor account-hygiene concern rather than evidence of weak maintenance capacity.
The top contributor made 70.3% of recent commits, which is concentrated, but 36 contributors were active and the repository is backed by an organization, reducing handoff risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-842079 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. openai is vulnerable to Path Traversal in versions 4.41.0 - 7.4.0. | 4.41.0 - 7.4.0 | Medium |
AIKIDO-2026-371568 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. openai is vulnerable to Information Disclosure in versions 4.41.0 - 7.4.0. | 4.41.0 - 7.4.0 | Medium |
AIKIDO-2026-445557 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. openai is vulnerable to Uncontrolled Resource Consumption in versions 5.8.0 - 7.5.0. | 5.8.0 - 7.5.0 | Medium |
AIKIDO-2026-767363 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. openai is vulnerable to Exposure of Sensitive Information in versions 7.6.0 - 7.7.0. | 7.6.0 - 7.7.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.