Passwordless authentication for Strapi v5 via magic links, email OTP and TOTP-based MFA. Drop-in replacement for password login.
62%
Total Score
50
83
67
100
The name overlaps with the much more downloaded package “link,” and the README identifies the lookalike, but artifact overlap is zero and the package does not borrow its identity; this warrants caution rather than a copy verdict.
The repository is owned by an individual rather than an organization, so the project has limited visible institutional backing; this matters more alongside zero recent commit activity.
The repository recorded zero commits and zero active maintainers in the last three months, despite a recent release; this weakens evidence of ongoing maintenance.
The repository uses npm build scripts but reports no security scanning tools, leaving a meaningful repository hygiene gap for an authentication plugin.
No security policy is present in the repository, which is a transparency gap for a plugin handling authentication, tokens, and multifactor credentials.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10626 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. strapi-plugin-magic-link-v5 is vulnerable to Authorization Bypass in versions 0.0.1 - 5.4.0. | 0.0.1 - 5.4.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^3.25.0 | — | — |
pino Version ^10.3.1 | — | — |
lodash Version ^4.18.1 | — | — |
nanoid Version ^3.3.11 | — | — |
qrcode Version ^1.5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.