Package Health

strapi-plugin-magic-link-v5

Passwordless authentication for Strapi v5 via magic links, email OTP and TOTP-based MFA. Drop-in replacement for password login.

Latest 5.5.9NPMNPM

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Name lookalikecaution

The name overlaps with the much more downloaded package “link,” and the README identifies the lookalike, but artifact overlap is zero and the package does not borrow its identity; this warrants caution rather than a copy verdict.

Project backingcaution

The repository is owned by an individual rather than an organization, so the project has limited visible institutional backing; this matters more alongside zero recent commit activity.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, despite a recent release; this weakens evidence of ongoing maintenance.

Repo toolingcaution

The repository uses npm build scripts but reports no security scanning tools, leaving a meaningful repository hygiene gap for an authentication plugin.

Security policycaution

No security policy is present in the repository, which is a transparency gap for a plugin handling authentication, tokens, and multifactor credentials.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10626 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
strapi-plugin-magic-link-v5 is vulnerable to Authorization Bypass in versions 0.0.1 - 5.4.0.
0.0.1 - 5.4.0
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
zod
Version ^3.25.0
—
—
pino
Version ^10.3.1
—
—
lodash
Version ^4.18.1
—
—
nanoid
Version ^3.3.11
—
—
qrcode
Version ^1.5.4
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago
Unpacked Size
1.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform