@cyberhub/trust-nuxt-kit
v1.0.0
Published
Security Trust Report for @nuxt/kit — 66/100 (B, standard). Maintainer risk and vulnerability analysis from 8 security databases.
Maintainers
Readme
Security Trust Report: @nuxt/kit
Score: 66/100 | Grade: B | Tier: STANDARD
This package has notable risk factors. Review flags below.
Score Breakdown
| Category | Score | |----------|-------| | Maintainer Trust | 82/100 | | Package Health | 91/100 | | Supply Chain | 29/100 | | Community | 47/100 |
Vulnerabilities
No known vulnerabilities.
Flags
- CRITICAL: Package name "@nuxt/kit" is 2 edit(s) from popular "koa"
- HIGH: Maintainer(s) removed in v3.15.0: clarkdo
- HIGH: Maintainer(s) removed in v3.19.0: atinux, pi0, antfu, danielroe
- HIGH: Depends on historically compromised package: semver
- HIGH: 1 direct dependencies have known security issues
- HIGH: Depends on "semver" which has ReDoS CVE-2022-25883
- MEDIUM: New maintainer(s) added in v4.4.2: danielroe
- MEDIUM: No GitHub repo found — community signals unavailable
- INFO: Published with 2FA enabled (signed)
- INFO: Package has provenance signatures
Maintainers
- nuxtbot (2FA)
- danielroe (2FA)
