The package also ships a clear README, license, release notes, and no install-time scripts. JavaScript consumers get no bundled type declarations, and the release has no build attestation.
91%
Total Score
100
100
95
100
50
No build provenance attestation is present, leaving publication origin less independently verifiable. This is a transparency limitation, moderated by the active, organization-backed repository and mature release history.
No type declarations are included, which is a minor integration gap for TypeScript consumers. It does not indicate maintenance or supply-chain weakness by itself.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-185433 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. thrift is vulnerable to Denial of Service (DoS) in versions 0.7.0 - 0.23.0. | 0.7.0 - 0.23.0 | Medium |
CVE-2026-43870 thrift is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 0.22.0. | 0.0.0 - 0.22.0 | High |
AIKIDO-2026-10700 thrift is vulnerable to Uncontrolled Recursion in versions 0.2.1 - 0.22.0. | 0.2.1 - 0.22.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ^8.21.0 | — | — |
uuid Version ^14.0.0 | — | — |
node-int64 Version ^0.4.0 | — | — |
isomorphic-ws Version ^4.0.1 | — | — |
browser-or-node Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.