Package Health

sm-crypto

A two-person contributor base, with one making 92% of recent commits, leaves limited resilience, and the project has no security-scanning tooling. Clear licensing, documentation, tests in the repository, and recent maintenance support adoption.

Latest 0.5.7NPMNPM

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation, trusted publisher, or staged publishing evidence is present. This reduces release transparency, though it is not by itself evidence that the package is unsafe.

Maintainerscaution

Only one registry account has publish access, which creates publishing concentration. The active source repository provides some compensating maintenance evidence, but not a second publisher.

Project backingcaution

The repository is owned by an individual account rather than an organization, so there is no organizational handoff signal to offset the concentrated contributor activity.

Repo bus factorcaution

Recent work is concentrated: one contributor made 11 of 12 commits, or about 92%, while the second made one. The active second contributor helps, but the project remains dependent on one primary maintainer.

Repo toolingcaution

The project uses webpack, Babel, and npm scripts, showing an established build process. It has no reported security-scanning tools, leaving a modest hygiene gap.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-139254
sm-crypto is vulnerable to NULL Pointer Dereference in versions 0.0.1 - 0.5.3.
0.0.1 - 0.5.3
Medium
AIKIDO-2026-859106
sm-crypto is vulnerable to Signature Malleability in versions 0.0.1 - 0.5.4.
0.0.1 - 0.5.4
Medium
CVE-2026-73567
sm-crypto is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in versions 0.0.0 - 0.5.0.
0.0.0 - 0.5.0
Critical
CVE-2026-23965
sm-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 0.4.0.
0.0.0 - 0.4.0
High
CVE-2026-23967
sm-crypto is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.0 - 0.3.14.
0.0.0 - 0.3.14
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
jsbn
Version ^1.1.0

Weekly Downloads

Info

Last Published
29 days ago
Created
8 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform