RFC9562 UUIDs
88%
Total Score
healthy
Active, well-backed project with fresh releases and contributors; workflow pinning and untrusted checkout are the main cautions.
The package declares prepack and prepare scripts. These are build or publication-related lifecycle hooks rather than evidence of a malicious install step, but they add some execution surface.
The project uses TypeScript, Rollup, Webpack, and npm scripts, showing an established build process; no security scanning tools were detected, which is a modest transparency gap.
All four workflows were analyzed, but all 10 action references are unpinned and browser.yml combines pull_request_target with an untrusted checkout. The sole cache-poisoning finding is low confidence and hygiene-level.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10892 uuid is vulnerable to Out-of-bounds Write in versions 0.0.1 - 10.0.0. | 0.0.1 - 10.0.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.