yargs the modern, pirate-themed, successor to optimist.
82%
Total Score
67
100
94
100
100
One contributor made 100% of the last three months' commits. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, leaving a genuine continuity risk.
Seven commits were made in the last three months, showing recent activity, but only one maintainer contributed during that period. The activity is real but narrow.
The repository uses TypeScript, npm scripts, and Babel, indicating an established build process. No security-scanning tool was detected, which is a minor transparency gap but not a severe dependency-health concern by itself.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-922647 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. yargs is vulnerable to Prototype Pollution in versions 0.0.1 - 18.0.0. | 0.0.1 - 18.0.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
y18n Version ^5.0.5 | — | — |
cliui Version ^9.0.1 | — | — |
escalade Version ^3.1.1 | — | — |
string-width Version ^8.2.1 | — | — |
yargs-parser Version ^22.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.