List of the 100,000 most commonly used passwords
45%
Total Score
75
100
69
100
The package is flagged as borrowing the identity of wikimedia/css-sanitizer, with borrows_lookalike_identity true, even though artifact overlap is 0.0 and the README does not identify it as a fork. This is a serious supply-chain transparency concern because consumers may have intended the lookalike package.
The package has 10 releases over about 9 years, but none in the last 12 months; its latest release was over a year before collection. This indicates a slow or paused release cadence for a package developers may depend on for an evolving password list.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the repository was pushed recently and contains tests, there is little evidence of current development activity.
The linked repository name does not match wikimedia/common-passwords and its README does not mention the package, so the package-to-source relationship is not clearly established. The matching Wikimedia organization provides some context but does not remove this transparency gap.
The repository uses Composer for builds, but no security scanning tools were detected. The build setup is present, while the missing scanning is a modest transparency gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.