Package Health

zod

Healthy and suitable to depend on. It has a long, active release history, current repository activity, strong testing and documentation, and verified build provenance. The main caveat is that most recent commits come from one maintainer and repository security scanning is absent.

Latest 4.6.5NPMNPM

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which creates publishing continuity risk. The active repository and high recent commit activity provide meaningful compensation, but not a second registry publisher.

Project backingcaution

The repository is owned by an individual rather than an organization, so the concentrated maintainer activity and single registry publisher represent a meaningful continuity risk.

Repo bus factorcaution

The leading contributor made 83.2% of recent commits, creating concentration risk. However, 14 other contributors were active during the same three-month period, which partly offsets but does not eliminate the dependency on one maintainer.

Repo toolingcaution

The repository uses established TypeScript, test, bundling, and build tooling. It has no security-scanning tools, leaving a genuine security-process gap despite otherwise mature development tooling.

Token permissionscaution

Four workflows lack top-level permissions and three declare top-level write access, which is weaker workflow hardening than ideal. The analysis still found no dangerous workflow patterns, partially limiting the concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-970919 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
zod is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.25.9 - 4.5.4.
3.25.9 - 4.5.4
Low
AIKIDO-2026-161437 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
zod is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.21.0 - 4.4.3.
3.21.0 - 4.4.3
Low
AIKIDO-2026-500926 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
zod is vulnerable to Prototype Pollution in versions 4.0.0 - 4.4.3.
4.0.0 - 4.4.3
Low
AIKIDO-2026-10707 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
zod is vulnerable to Prototype Pollution in versions 1.0.0 - 4.3.6.
1.0.0 - 4.3.6
Medium
AIKIDO-2026-10706 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
zod is vulnerable to Improper Input Validation in versions 1.0.0 - 4.3.6.
1.0.0 - 4.3.6
Medium

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
13 days ago
Created
6 years ago
Unpacked Size
5.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform