Package Health

openapi-backend

Build, Validate, Route, Authenticate and Mock using OpenAPI definitions. Framework-agnostic

Latest 5.21.2NPMNPM

92%

Total Score

healthy

Healthy: active releases and repository maintenance support a dependable 5.21.2.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

Both workflows were analyzed without file failures, and there are no untrusted checkouts or script injections. However, all 11 action references are unpinned and one workflow has top-level write permissions; the two low-confidence cache-poisoning findings are hygiene concerns rather than standalone severe risks.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-314365 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
openapi-backend is vulnerable to Authorization Bypass in versions 5.5.0 - 5.17.0.
5.5.0 - 5.17.0
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
qs
Version ^6.15.0
—
—
ajv
Version ^8.6.2
—
—
cookie
Version ^1.1.1
—
—
lodash
Version ^4.17.15
—
—
bath-es5
Version ^3.0.3
—
—

Weekly Downloads

Info

Last Published
8 days ago
Created
7 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform