Clear documentation, typings, and release notes support integration. The package is mature and actively developed, though deployment teams should account for its install-time scripts.
82%
Total Score
100
100
67
50
No build attestation or trusted-publisher identity is present, leaving publication provenance less verifiable. The strong repository and release activity partly compensate, but do not remove the gap.
The package runs postinstall and prepare scripts, which add install-time behavior that consumers should understand. No provided signal shows those scripts are unsafe, so this is a limited transparency concern.
All seven workflows were analyzed and none uses untrusted checkout or risky pull-request triggers, but all 72 action references are unpinned and high-confidence template-injection and unpinned-image findings remain. The low-confidence cache findings are hygiene concerns rather than decisive risks.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-898030 parse-server is vulnerable to Information Disclosure in versions 8.2.2 - 8.6.86 and 9.0.0 - 9.9.0. | 8.2.2 - 8.6.869.0.0 - 9.9.0 | Medium |
CVE-2026-55778 parse-server is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 9.0.0 - 9.9.1-alpha.11 and 0.0.0 - 8.6.80. | 0.0.0 - 8.6.809.0.0 - 9.9.1-alpha.11 | Low |
CVE-2026-53725 parse-server is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 9.8.0 - 9.9.1-alpha.5. | 9.8.0 - 9.9.1-alpha.5 | Medium |
CVE-2026-50008 parse-server is vulnerable to Incorrect Authorization in versions 9.8.0 - 9.9.1-alpha.3. | 9.8.0 - 9.9.1-alpha.3 | Medium |
AIKIDO-2026-11108 parse-server is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 8.6.78 and 9.0.0 - 9.9.1-alpha.3. | 0.0.1 - 8.6.789.0.0 - 9.9.1-alpha.3 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 8.21.3 | — | — |
tv4 Version 1.3.0 | — | — |
cors Version 2.8.6 | — | — |
mime Version 4.1.0 | — | — |
parse Version 8.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.