SockJS-node is a server counterpart of SockJS-client a JavaScript library that provides a WebSocket-like object in the browser. SockJS gives you a coherent, cross-browser, Javascript API which creates a low latency, full duplex, cross-domain communication
60%
Total Score
75
100
79
75
50
The package has 36 releases, but its latest release was in December 2021 and it had no releases in the last 12 months, indicating substantial maintenance risk.
The release has no build attestation, trusted publisher identity, or staged publishing, leaving the connection between source and registry artifact less transparent.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the long release gap and raising abandonment concerns.
No build tooling or security scanning tools were detected in the repository, which is a modest maintenance and assurance gap for a package with no recent release activity.
The workflow audit completed cleanly with no high- or medium-severity findings and no untrusted checkout or injection sinks, but both analyzed action references are unpinned, weakening reproducibility and update safety.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-7693 sockjs is vulnerable to Improper Input Validation in versions 0.0.0 - 0.3.20. | 0.0.0 - 0.3.20 | Medium |
CVE-2020-8823 sockjs is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 0.3.0. | 0.0.0 - 0.3.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
uuid Version ^8.3.2 | — | — |
faye-websocket Version ^0.11.3 | — | — |
websocket-driver Version ^0.7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.