super fast, all natural json logger
82%
Total Score
healthy
Healthy, with workflow hygiene concerns from mostly unpinned Actions and an ad-hoc package install.
The audit analyzed all 5 workflows and found no untrusted checkout or script-injection counts, but 13 of 15 action references are unpinned and a high-confidence adhoc-packages finding installs outside a lockfile. High-confidence template-injection findings in the release workflow add workflow hygiene concern, though no corroborating dangerous trigger-and-sink combination was reported.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10046 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. pino is vulnerable to Prototype Pollution in versions 7.2.0 - 10.1.0. | 7.2.0 - 10.1.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
sonic-boom Version ^4.0.1 | — | — |
atomic-sleep Version ^1.0.0 | — | — |
real-require Version ^1.0.0 | — | — |
thread-stream Version ^4.0.0 | — | — |
@pinojs/redact Version ^0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.