Clear documentation, TypeScript declarations, tests, release notes, and no runtime dependencies make integration straightforward. Maintenance is thin: only one commit in three months, one active contributor, and no security policy, so pin this version and monitor it.
68%
Total Score
50
100
94
75
50
No build attestation or trusted-publishing provenance is present, leaving the origin of the published artifact less transparent.
The package is mature, with 70 releases since 2017 and a release in the last 12 months, but the recent cadence is sparse at one release in that period.
One contributor made all commits in the last three months, leaving maintenance dependent on a single active contributor.
Only one commit was recorded in the last three months, indicating very light recent maintenance despite the latest release being recent.
The repository has open issues and pull requests, but no new or closed issues and no merged pull requests in the last month, consistent with limited recent activity.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-273611 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. squirrelly is vulnerable to Code Injection in versions 8.0.0 - 9.1.0. | 8.0.0 - 9.1.0 | High |
CVE-2024-40453 squirrelly is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 9.0.0 - 9.1.0. | 9.0.0 - 9.1.0 | Critical |
CVE-2021-32819 squirrelly is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 8.0.8. | 0.0.0 - 8.0.8 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.