Package Health

superjson

Latest 2.2.6NPMNPM

80%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance was detected, leaving publication origin less verifiable. This is a transparency caution, balanced by the package's long release history and linked source repository.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.

Security policycaution

No repository security policy was found, reducing the project's published guidance for reporting vulnerabilities. This is a transparency gap, not a standalone dependency blocker.

Workflow auditcaution

The single workflow was fully analyzed with no audit findings or untrusted checkouts, but all 3 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2024-10514 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
superjson is vulnerable to Denial of Service (DoS) in versions 1.2.0 - 2.2.1.
1.2.0 - 2.2.1
Low
CVE-2022-23631
superjson is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.8.1.
0.0.0 - 1.8.1
Critical

Package versions

Direct Dependencies

DependencyLast ReleaseScore
copy-anything
Version ^4
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
11 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform