Fast, lightweight JSON Schema validator for Node.js and browsers — full support for draft-04, draft-06, draft-07, draft-2019-09, and draft-2020-12 (latest)
72%
Total Score
caution
Frequent releases are offset by one-person maintenance and workflow weaknesses, including unpinned actions and a high-confidence injection finding.
A prepare install-time script is present. This adds build-time execution during installation, but the signal does not show that it is harmful or unusually complex.
Only one registry account has publish access. That is a real publishing continuity concern because no second registry maintainer is shown.
The repository is owned by an individual user rather than an organization, so the single-contributor and single-publisher concentration is not compensated by visible organizational backing.
All 21 recent commits came from one contributor, giving the project a high maintenance concentration and increasing continuity risk.
No repository security policy was found, leaving vulnerability-reporting expectations and ownership less transparent.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10450 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. z-schema is vulnerable to Prototype Pollution in versions 3.0.0 - 12.0.4. | 3.0.0 - 12.0.4 | Medium |
AIKIDO-2026-10449 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. z-schema is vulnerable to Regular Expression Denial-of-service (ReDoS) in versions 7.1.0 - 12.0.4. | 7.1.0 - 12.0.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
punycode Version ^2.3.1 | — | — |
validator Version ^13.15.26 | — | — |
safe-regex2 Version ^5.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.