Package Health

ws

Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js

Latest 8.22.0NPMNPM

88%

Total Score

healthy

Healthy: long-running, actively maintained, tested and licensed release with only minor workflow and typing gaps.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is recorded, which reduces publication transparency, although the package has strong repository and release-history evidence.

Type declarationscaution

No type declarations are published, which makes integration less convenient for TypeScript consumers of this library.

Workflow auditcaution

The workflow audit is complete with no reported findings, read-only permissions, and no untrusted checkout or script-injection paths. However, all 4 action references are unpinned, leaving a supply-chain hygiene gap.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-138234
ws is vulnerable to Denial of Service (DoS) in versions 5.2.5 - 5.2.5, 6.2.4 - 6.2.4, 7.5.11 - 7.5.11 and 8.21.0 - 8.21.0.
5.2.5 - 5.2.56.2.4 - 6.2.47.5.11 - 7.5.11 +1 more
High
CVE-2026-48779
ws is vulnerable to Uncontrolled Resource Consumption in versions 1.1.0 - 5.2.5, 6.0.0 - 6.2.4, 7.0.0 - 7.5.11 and 8.0.0 - 8.21.0.
1.1.0 - 5.2.56.0.0 - 6.2.47.0.0 - 7.5.11 +1 more
High
CVE-2026-45736
ws is vulnerable to Use of Uninitialized Resource in versions 8.0.0 - 8.20.1.
8.0.0 - 8.20.1
Medium
CVE-2024-37890
ws is vulnerable to NULL Pointer Dereference in versions 2.1.0 - 5.2.4, 6.0.0 - 6.2.3, 7.0.0 - 7.5.10 and 8.0.0 - 8.17.1.
2.1.0 - 5.2.46.0.0 - 6.2.37.0.0 - 7.5.10 +1 more
High
CVE-2021-32640
ws is vulnerable to Insufficient Verification of Data Authenticity in versions 7.0.0 - 7.4.6, 6.0.0 - 6.2.2 and 5.0.0 - 5.2.3.
5.0.0 - 5.2.36.0.0 - 6.2.27.0.0 - 7.4.6
Medium

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
15 days ago
Created
14 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform