This module provides native bindings to ecdsa secp256k1 functions
72%
Total Score
63
100
94
50
An install lifecycle script is present, which means installation performs build-related work and adds supply-chain exposure compared with a package requiring no install execution.
All 2 recent commits came from one contributor, concentrating current maintenance capacity; organization backing provides some ability to hand work to others but does not show a second active contributor.
Only 2 commits were made in the last 3 months, indicating a low recent maintenance pace, although the package itself had a recent release.
The repository has 13 open issues and 4 open pull requests, with one issue closed in the last month; this shows some maintenance activity but limited recent throughput.
The project uses make and npm build tooling, but no security-scanning tools were detected, leaving a modest transparency and hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-48930 secp256k1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0 - 5.0.0, 4.0.0 - 4.0.4 and 0.0.0 - 3.8.0. | 0.0.0 - 3.8.04.0.0 - 4.0.45.0.0 - 5.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
elliptic Version ^6.5.7 | — | — |
node-addon-api Version ^5.0.0 | — | — |
node-gyp-build Version ^4.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.