Official Node SDK for Razorpay API
72%
Total Score
88
100
94
50
50
No build attestation or trusted publisher identity is present. The active organization-backed repository and published release notes provide some transparency, but artifact origin is not independently attested.
A prepublish lifecycle script runs during publishing. This is a mild supply-chain and reproducibility consideration, although the signal does not show an install-time script executed by consumers.
The package is mature at roughly 10 years old with 40 releases, but only one release occurred in the last 12 months. Active repository commits partly compensate, though the registry cadence is relatively sparse.
The repository has 72 open issues and 61 open pull requests, with no issues closed in the last month and no pull requests merged. Two new pull requests show some activity, but backlog resolution is weak.
No security policy file was found in the repository. Dependabot and Semgrep provide some security practice, but they do not replace clear vulnerability-reporting guidance.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10095 razorpay is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 2.9.3. | 0.0.0 - 2.9.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
axios Version ^1.18.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.