Parses set-cookie headers into objects
88%
Total Score
healthy
Long-lived package with recent releases and commits; unpinned workflow actions and no repository security policy reduce transparency.
A prepare lifecycle script runs during installation or publication. This is a mild supply-chain and reproducibility consideration, although the signal does not show that the script is unsafe.
Two contributors were active recently, with the top contributor responsible for two-thirds of commits; this is somewhat concentrated but not a single-contributor project.
The project uses npm build tooling, but no repository security-scanning tool was detected, leaving a modest security-process gap.
No security policy was found in the repository, reducing the transparency of vulnerability reporting and response expectations.
The single workflow was fully analyzed with no audit findings, no untrusted checkout or script-injection paths, and job-level permissions. All 4 action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10763 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. set-cookie-parser is vulnerable to Prototype Pollution in versions 2.0.0 - 2.7.1. | 2.0.0 - 2.7.1 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.