Package Health

qs

A querystring parser that supports nesting and arrays, with a depth limit

Latest 6.16.0NPMNPM

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation is present, so consumers have less independently verifiable evidence connecting the published artifact to its source. Staged publishing and an approver provide some compensating release control.

Dangerous workflowscaution

Two workflows use pull_request_target and therefore deserve review, but none uses untrusted checkouts or detected script injection. The observed workflow profile is a limited caution rather than a severe health risk.

Lifecycle scriptscaution

The package uses prepack and prepublish lifecycle scripts, adding install or publication complexity. This is a supply-chain consideration, though the broader repository and release evidence shows an established project.

Repo bus factorcaution

One maintainer made 32 of 36 recent commits, creating concentration risk despite four other contributors remaining active. The repository is user-owned rather than organization-owned, so this concentration is a genuine caveat.

Token permissionscaution

Five workflows declare read-only permissions, while only rebase.yml has top-level write permissions. This is mostly restrictive, with one higher-privilege workflow warranting review.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-81971
qs is vulnerable to Denial of Service (DoS) in versions 2.2.5 - 6.15.3.
2.2.5 - 6.15.3
Medium
AIKIDO-2026-35535
qs is vulnerable to Denial of Service (DoS) in versions 6.14.2 - 6.15.3.
6.14.2 - 6.15.3
Low
CVE-2026-8723
qs is vulnerable to NULL Pointer Dereference in versions 6.11.1 - 6.15.1.
6.11.1 - 6.15.1
Medium
CVE-2026-2391
qs is vulnerable to Improper Input Validation in versions 6.7.0 - 6.14.1.
6.7.0 - 6.14.1
Low
CVE-2025-15284
qs is vulnerable to Improper Input Validation in versions 0.0.0 - 6.14.1.
0.0.0 - 6.14.1
Low

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
side-channel
Version ^1.1.1
—
—
es-define-property
Version ^1.0.1
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
15 years ago
Unpacked Size
0.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform