Healthy and suitable to depend on. It has a long, active release history, current repository work, strong project hygiene, and clear organizational backing; maintenance is concentrated in one contributor but two others remain active.
88%
Total Score
88
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-246457 New web-auth/cose-lib is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.1 - 4.7.1. | 0.0.1 - 4.7.1 | Medium |
AIKIDO-2026-767492 New web-auth/cose-lib is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 4.7.1. | 0.0.1 - 4.7.1 | Medium |
AIKIDO-2026-747353 New web-auth/cose-lib is vulnerable to Private Key Recovery in versions 2.1.0 - 4.7.1. | 2.1.0 - 4.7.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.9 || ^0.10 || ^0.11 || ^0.12 || ^0.13 || ^0.14 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0 | — | — |
spomky-labs/pki-framework Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.