Healthy and suitable to depend on. It has a long, active release history, current repository activity, strong testing and documentation, and verified build provenance. The main caveat is that most recent commits come from one maintainer and repository security scanning is absent.
91%
Total Score
70
95
90
100
Only one registry account has publish access, which creates publishing continuity risk. The active repository and high recent commit activity provide meaningful compensation, but not a second registry publisher.
The repository is owned by an individual rather than an organization, so the concentrated maintainer activity and single registry publisher represent a meaningful continuity risk.
The leading contributor made 83.2% of recent commits, creating concentration risk. However, 14 other contributors were active during the same three-month period, which partly offsets but does not eliminate the dependency on one maintainer.
The repository uses established TypeScript, test, bundling, and build tooling. It has no security-scanning tools, leaving a genuine security-process gap despite otherwise mature development tooling.
Four workflows lack top-level permissions and three declare top-level write access, which is weaker workflow hardening than ideal. The analysis still found no dangerous workflow patterns, partially limiting the concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-970919 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. zod is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.25.9 - 4.5.4. | 3.25.9 - 4.5.4 | Low |
AIKIDO-2026-161437 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. zod is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.21.0 - 4.4.3. | 3.21.0 - 4.4.3 | Low |
AIKIDO-2026-500926 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. zod is vulnerable to Prototype Pollution in versions 4.0.0 - 4.4.3. | 4.0.0 - 4.4.3 | Low |
AIKIDO-2026-10707 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. zod is vulnerable to Prototype Pollution in versions 1.0.0 - 4.3.6. | 1.0.0 - 4.3.6 | Medium |
AIKIDO-2026-10706 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. zod is vulnerable to Improper Input Validation in versions 1.0.0 - 4.3.6. | 1.0.0 - 4.3.6 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.