Package Health

statsig-node

Statsig Node.js SDK for usage in multi-user server environments.

Latest 6.5.2NPMNPM

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity is present. This leaves release origin less transparent, though it is a supply-chain transparency gap rather than proof of unsafe code.

Lifecycle scriptscaution

The package runs a prepare install-time lifecycle script. This adds build or installation behavior that consumers must account for, although the signal does not show malicious or unusually risky commands.

Repo bus factorcaution

All 1 recent commit came from one contributor, giving a 100% top-contributor share. Organization ownership partly offsets the handoff risk, but no second active contributor is shown in this period.

Repo commit activitycaution

Only 1 commit was recorded in the last 3 months, with 1 active maintainer. That recent activity is thin for a maintained SDK and raises slowing-maintenance concerns.

Repo issue activitycaution

The repository has 7 open issues and 2 open pull requests, but recorded activity shows no new or closed issues and no merged pull requests in the last month. This is a mild sign of limited current engagement.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10530 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
statsig-node is vulnerable to Insertion of Sensitive Information into Log File in versions 5.11.0 - 6.4.4.
5.11.0 - 6.4.4
Low
AIKIDO-2024-10209 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
statsig-node is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in versions 5.20.0 - 5.25.0.
5.20.0 - 5.25.0
Medium
AIKIDO-2024-10171 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
statsig-node is vulnerable to Insertion of Sensitive Information into Log File in versions 5.11.0 - 5.23.0.
5.11.0 - 5.23.0
Low

Package versions

Direct Dependencies

DependencyLast ReleaseScore
uuid
Version ^11.1.1
—
—
ip3country
Version ^5.0.0
—
—
node-fetch
Version ^2.7.0
—
—
ua-parser-js
Version ^1.0.2
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago
Unpacked Size
1.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform