The package has a long release history, clear licensing, bundled typings, tests, and organization-backed source. Maintenance is currently quiet, and all six workflow action references are unpinned, so pinning this version is preferable.
73%
Total Score
75
50
94
75
50
Staged publishing with an approver provides some process control, but no build attestation is available, leaving publication provenance less transparent.
Six runtime dependencies form a moderate dependency surface for a cryptographic compatibility library; this adds some transitive maintenance exposure but is not excessive on its own.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful sign of currently quiet maintenance despite the recent release history.
TypeScript build tooling is present, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
All six workflows were analyzed with no audit findings and no untrusted checkouts or script-injection sinks. However, all six action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-6547 pbkdf2 is vulnerable to Improper Input Validation in versions 1.0.0 - 3.1.2. | 1.0.0 - 3.1.2 | Critical |
CVE-2025-6545 pbkdf2 is vulnerable to Improper Input Validation in versions 3.0.10 - 3.1.2. | 3.0.10 - 3.1.2 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
sha.js Version ^2.4.12 | — | — |
ripemd160 Version ^2.0.3 | — | — |
to-buffer Version ^1.2.2 | — | — |
create-hash Version ^1.2.0 | — | — |
create-hmac Version ^1.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.