Generic extension manager for WebSocket connections
65%
Total Score
50
100
90
50
Only one registry account has publish access, which weakens publishing resilience. The repository is owned by an organization, so this is a smaller concern than it would be for an independently owned project.
The package has had no releases in the last 12 months, and its latest release was in June 2020, more than 6 years before this assessment. This is meaningful maintenance risk, though the repository is not archived and was pushed in September 2023.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no current development activity. Its non-archived status provides some continuity but does not offset the recent inactivity.
The repository has no security policy, reducing transparency around vulnerability reporting and maintenance expectations. This is a hygiene gap rather than evidence that the release is unsafe.
The sole workflow was fully analyzed with no untrusted checkout or script-injection findings, but both action references are unpinned and it installs a package outside a lockfile. These are limited workflow-reproducibility concerns, not severe risks.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-7662 websocket-extensions is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 0.1.4. | 0.0.0 - 0.1.4 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.