Parses a link header and returns paging information for each contained link.
58%
Total Score
50
100
86
50
50
The release has no build attestation or trusted-publisher record. This is a supply-chain transparency gap, while the package remains licensed and the repository matches the package.
The package has nine releases since June 2013, but none in the last 12 months and the latest release was in December 2021. This indicates materially slowed maintenance for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. The repository is not archived, but current maintenance activity is absent.
No build tools or security scanning tools were detected. The small package has tests and a simple structure, which partly offsets this tooling gap.
The repository has no security policy. This reduces transparency for reporting and handling issues, though it is not evidence of unsafe code by itself.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-23490 parse-link-header is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 2.0.0. | 0.0.0 - 2.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
xtend Version ~4.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.