Package Health

secp256k1

This module provides native bindings to ecdsa secp256k1 functions

Latest 5.0.2NPMNPM

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

An install lifecycle script is present, which means installation performs build-related work and adds supply-chain exposure compared with a package requiring no install execution.

Repo bus factorcaution

All 2 recent commits came from one contributor, concentrating current maintenance capacity; organization backing provides some ability to hand work to others but does not show a second active contributor.

Repo commit activitycaution

Only 2 commits were made in the last 3 months, indicating a low recent maintenance pace, although the package itself had a recent release.

Repo issue activitycaution

The repository has 13 open issues and 4 open pull requests, with one issue closed in the last month; this shows some maintenance activity but limited recent throughput.

Repo toolingcaution

The project uses make and npm build tooling, but no security-scanning tools were detected, leaving a modest transparency and hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-48930
secp256k1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0 - 5.0.0, 4.0.0 - 4.0.4 and 0.0.0 - 3.8.0.
0.0.0 - 3.8.04.0.0 - 4.0.45.0.0 - 5.0.0
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
elliptic
Version ^6.5.7
—
—
node-addon-api
Version ^5.0.0
—
—
node-gyp-build
Version ^4.2.0
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
12 years ago
Unpacked Size
1.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform