Snapshotable JavaScript runtime via WebAssembly. QuickJS-NG compiled to WASM with snapshot/restore support.
88%
Total Score
100
100
100
75
100
No security policy was found in the repository, leaving vulnerability reporting expectations less clear for a runtime package.
Both workflows were analyzed successfully with no unsafe-trigger sinks or audit findings, but all seven action references are unpinned, which weakens build reproducibility and action supply-chain control.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-657657 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. quickjs-wasi is vulnerable to Uncontrolled Resource Consumption in versions 0.1.0 - 3.3.0. | 0.1.0 - 3.3.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.