@cyberhub/trust-jsonwebtoken
v1.0.0
Published
Security Trust Report for jsonwebtoken — 64/100 (C+, standard). Maintainer risk and vulnerability analysis from 8 security databases.
Maintainers
Readme
Security Trust Report: jsonwebtoken
Score: 64/100 | Grade: C+ | Tier: STANDARD
This package has notable risk factors. Review flags below.
Score Breakdown
| Category | Score | |----------|-------| | Maintainer Trust | 62/100 | | Package Health | 94/100 | | Supply Chain | 47/100 | | Community | 47/100 |
Vulnerabilities
No known vulnerabilities.
Flags
- CRITICAL: HISTORICAL BREACH: Algorithm confusion attack CVE-2022-23529 (2022)
- HIGH: Maintainer(s) removed in v9.0.1: jstrutz
- HIGH: Maintainer(s) removed in v9.0.2: julien.wollscheid, jake.lacey, lbalmaceda, ziluvatar, woloski, jfromaniello, iaco, dschenkelman, madhuri.rm23, edgarchirivella-okta
- HIGH: Maintainer(s) removed in v9.0.3: timferrell
- HIGH: 1 direct dependencies have known security issues
- HIGH: Depends on "semver" which has ReDoS CVE-2022-25883
- MEDIUM: New maintainer(s) added in v9.0.1: david.renaud.okta, madhuri.rm23, edgarchirivella-okta
- MEDIUM: New maintainer(s) added in v9.0.2: timferrell
- MEDIUM: New maintainer(s) added in v9.0.3: julien.wollscheid, javierquevedo
- MEDIUM: No GitHub repo found — community signals unavailable
Maintainers
- charlesrea (2FA)
- madhuri.rm23 (2FA)
- julien.wollscheid (2FA)
- javierquevedo (2FA)
