Package Health

StackExchange.Redis.Extensions.Core

A single maintainer makes continuity more dependent on one person, despite a second recent contributor. Workflow references are all unpinned, though the repository has active security scanning, a security policy, and no high-confidence workflow risks.

Latest 13.0.1NuGetNuGet

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Name lookalikecaution

The name resembles StackExchange.Redis and explicitly identifies that project in its README, which can confuse consumers even though the lower artifact overlap and extension description indicate a related library rather than a direct copy.

Project backingcaution

The repository is owned by an individual rather than an organization, so the concentrated contributor activity is not offset by clear organizational handoff capacity.

Repo bus factorcaution

Two contributors were active recently, but the leading contributor made about 84% of the commits. This leaves maintenance continuity concentrated in one person.

Repo issue activitycaution

The repository has only 8 open issues and 1 open pull request, but there was no issue or pull-request activity in the last month. This is a minor maintenance concern rather than evidence of abandonment because recent commits and releases are present.

Workflow auditcaution

All three workflows were analyzed with no untrusted checkout, script injection, or high-confidence severe findings. However, all 10 action references are unpinned, and the audit identified trusted publishing as a lower-severity workflow concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-374560 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
StackExchange.Redis.Extensions.Core is vulnerable to Code Injection in versions 10.1.0 - 13.0.0.
10.1.0 - 13.0.0
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
stackexchange.redis
Version [2.12.14, 4.0.0)
system.runtime.compilerservices.unsafe
Version [6.1.2, )

Weekly Downloads

Info

Last Published
1 month ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform