Package Health

serverless

[![Serverless Framework AWS Lambda AWS DynamoDB AWS API Gateway](https://github.com/serverless/serverless/assets/2752551/66a8c6a9-bc4a-4116-b139-90c12963337e)](https://serverless.com)

Latest 4.43.0NPMNPM

82%

Total Score

healthy

Healthy release with strong maintenance and provenance; concentrated recent development is the main caveat.

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

A postinstall script runs during installation, adding execution-time complexity and requiring more trust than a package without install hooks.

Repo bus factorcaution

One contributor made about 96% of the 99 recent commits, creating a real concentration risk, although two additional contributors remained active and the repository is organization-owned.

Workflow auditcaution

All eight workflows were analyzed and all 38 action references are pinned, with no untrusted checkout or script-injection findings. Six workflows grant top-level write access, and high-confidence archived-action and ad hoc package findings remain hygiene concerns.

Vulnerabilities

TitleVersionsSeverity
CVE-2025-69256
serverless is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 4.29.0 - 4.29.3.
4.29.0 - 4.29.3
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
undici
Version 6.28.1
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
10 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform