Package Health

vm2

vm2 3.12.2 appears to be a mature, actively maintained, and transparently published package: it has 83 releases over roughly 12 years, 18 releases in the last 12 months, a stable non-prerelease version, recent repository activity, build provenance, a matching source repository, and a documented security policy. The package artifact is small and lacks bundled tests and a changelog, but the repository contains both, which compensates for that artifact-level gap. The main reservations are that recent work is concentrated among two contributors, repository security-scanning tooling was not detected, and the workflows do not declare top-level permissions; these are meaningful hygiene concerns for a security-sensitive sandbox, but they do not outweigh the strong maintenance and provenance evidence.

Latest 3.12.2NPMNPM

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed, which creates some publishing continuity risk; the repository activity provides partial operational support but does not eliminate reliance on that account.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational succession signal; this is partly offset by two active recent contributors and substantial release activity.

Repo toolingcaution

The project uses esbuild and npm scripts, but no security-scanning tools were detected; for a package whose purpose is sandboxing untrusted code, this is a genuine security-process gap.

Token permissionscaution

All 3 workflows lack top-level permissions declarations, although none declares top-level write permissions and each uses job-level permissions; explicit least-privilege defaults would provide stronger CI hygiene.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-920930
vm2 is vulnerable to Sandbox Escape in versions 3.11.0 - 3.12.0.
3.11.0 - 3.12.0
Critical
AIKIDO-2026-916119
vm2 is vulnerable to Improper Access Control in versions 3.11.7 - 3.12.0.
3.11.7 - 3.12.0
High
AIKIDO-2026-290529
vm2 is vulnerable to Sandbox Escape in versions 0.1.0 - 3.12.1.
0.1.0 - 3.12.1
Critical
AIKIDO-2026-750176
vm2 is vulnerable to Sandbox Escape in versions 3.9.6 - 3.12.0.
3.9.6 - 3.12.0
Critical
AIKIDO-2026-793925
vm2 is vulnerable to Denial of Service in versions 0.1.0 - 3.12.1.
0.1.0 - 3.12.1
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
acorn
Version ^8.15.0
—
—
acorn-walk
Version ^8.3.4
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
12 years ago
Unpacked Size
1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform