JavaScript package downloader
68%
Total Score
67
100
100
83
100
All recent repository commits came from one contributor, creating concentration risk; the organization's ownership provides some capacity to hand maintenance off but does not remove the recent inactivity concern.
Only one commit was recorded in the last three months, indicating weak recent source activity despite the package's strong longer-term release history.
The audit covered all eight workflows, but found high-confidence template-injection findings and all 38 action references are unpinned; four workflows also grant top-level write permissions. No untrusted checkout, script-injection, pull_request_target, or workflow_run path was found, so these are serious hygiene concerns rather than a standalone severe dependency risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-9496 pacote is vulnerable to Uncontrolled Resource Consumption in versions 11.2.7 - 21.5.1. | 11.2.7 - 21.5.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
tar Version ^7.4.3 | — | — |
ssri Version ^14.0.0 | — | — |
cacache Version ^21.0.1 | — | — |
minipass Version ^7.0.2 | — | — |
proc-log Version ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.