XMLHttpRequest for Node
62%
Total Score
50
88
67
Only one registry publisher is listed, leaving a thin publishing base; the repository is user-owned rather than organization-backed, so there is no shown organizational compensation.
The package has existed since 2015 with 16 releases, but it had no releases in the last 12 months, indicating slowed maintenance.
There were zero commits and zero active maintainers in the last three months, a concrete sign that ongoing maintenance has slowed.
The repository reports no build tools and no security scanning, leaving limited evidence of repeatable builds or proactive security hygiene.
The repository has no security policy, which reduces transparency about how vulnerability reports are handled.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-31597 xmlhttprequest-ssl is vulnerable to Improper Certificate Validation in versions 0.0.0 - 1.6.1. | 0.0.0 - 1.6.1 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.