A two-person contributor base, with one making 92% of recent commits, leaves limited resilience, and the project has no security-scanning tooling. Clear licensing, documentation, tests in the repository, and recent maintenance support adoption.
82%
Total Score
70
100
90
100
50
No build attestation, trusted publisher, or staged publishing evidence is present. This reduces release transparency, though it is not by itself evidence that the package is unsafe.
Only one registry account has publish access, which creates publishing concentration. The active source repository provides some compensating maintenance evidence, but not a second publisher.
The repository is owned by an individual account rather than an organization, so there is no organizational handoff signal to offset the concentrated contributor activity.
Recent work is concentrated: one contributor made 11 of 12 commits, or about 92%, while the second made one. The active second contributor helps, but the project remains dependent on one primary maintainer.
The project uses webpack, Babel, and npm scripts, showing an established build process. It has no reported security-scanning tools, leaving a modest hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-139254 sm-crypto is vulnerable to NULL Pointer Dereference in versions 0.0.1 - 0.5.3. | 0.0.1 - 0.5.3 | Medium |
AIKIDO-2026-859106 sm-crypto is vulnerable to Signature Malleability in versions 0.0.1 - 0.5.4. | 0.0.1 - 0.5.4 | Medium |
CVE-2026-73567 sm-crypto is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in versions 0.0.0 - 0.5.0. | 0.0.0 - 0.5.0 | Critical |
CVE-2026-23965 sm-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 0.4.0. | 0.0.0 - 0.4.0 | High |
CVE-2026-23967 sm-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 0.3.14. | 0.0.0 - 0.3.14 | High |
| Dependency | Last Release | Score |
|---|---|---|
jsbn Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.