Skip to content
Tools / statping-ng / Security

Security Deep Dive

statping-ng

Security posture and CVE patch evidence from tracked releases.

Back to Tool

2 open KEV CVEs affects v0.93.0.

KEV-listed CVEs are confirmed exploited in the wild — patch urgently.

✗ Signed ✗ SLSA ✓ SBOM ✗ Security policy Unknown cadence Dormant maintainer

Trust Signals — 2 of 9 Present

Evidence already collected from releases and repository metadata.

2/9 Present
Signed releases Absent
Latest release artifact signature None
Last verified: 26d ago
SLSA provenance Absent
Attestation predicate level Latest release
Last verified: 26d ago
SBOM published Present
GitHub SBOM API Latest release
Last verified: 28d ago
SECURITY.md Absent
GitHub repository metadata Repository policy
Checked: 17d ago
Release cadence Unknown
12-release median Release history
Latest release: 12mo ago
Maintainer dormant Present
Recent commit activity Repository
Last commit: 12mo ago
Checksums (SHA256SUMS) Not active yet
SHA256SUMS or equivalent Release asset
Latest release: 12mo ago
GitHub Actions attestation Not active yet
actions/attest-build-provenance Workflow file
Latest release: 12mo ago
Signing assets Not active yet
.sig, .crt, cosign.pub, or similar Release asset
Latest release: 12mo ago
2.0/10 Security Score
3.2/10 Scorecard
Dependency Exposure 201 transitive dependency CVEs found in the latest SBOM. 17 critical.

Security Score

A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.

epss

0.25 / 0.5

No EPSS data

freshness

0.00 / 1.0

364d stale

scorecard

1.28 / 4.0

Score 3.2/10

cve health

0.00 / 2.5

⚠ No direct scan — 17c/72h transitive CVEs

patch speed

0.50 / 0.5

⚠ Estimated — no CVE patch history

kev exposure

1.50 / 1.5

No KEV exposure

supply chain risk

-1.50 / 10.0

Risk 100.0/100

Score breakdown

schema v2

Vulnerability posture

vulnerability posture

0.0

25%

direct cves: clear cve scan: estimated

Release responsiveness

release responsiveness

10.0

5%

patch speed days: no_history

Dependency exposure

dependency exposure

0.0

10%

supply chain risk: 100.0 transitive cves: 17c/72h

Provenance trust

provenance trust

3.2

40%

scorecard score: 3.2 openssf badge: none

Maintainer health

maintainer health

0.0

10%

activity freshness: 364d

Operational risk

operational risk

8.5

10%

kev exposure: detected epss max: none
How is this calculated?

The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.

Supply Chain Risk

Risk 100.0/100
17 Transitive critical CVEs
2 KEV-transitive CVEs
67% Dependency freshness

Scorecard

Scorecard 3.2/10

OpenSSF Scorecard evaluates supply-chain security practices automatically. Score ≥ 6 is passing; ≥ 8 is excellent.

Check Score Reason
Code-Review 4 Found 10/22 approved changesets -- score normalized to 4
Maintained 0 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Packaging -1 packaging workflow not detected
CII-Best-Practices 0 no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow 10 no dangerous workflow patterns detected
Token-Permissions 0 detected GitHub workflow tokens with excessive permissions
Binary-Artifacts 10 no binaries found in the repo
Security-Policy 0 security policy file not detected
Fuzzing 0 project is not fuzzed
License 10 license file detected
Branch-Protection -1 internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases 0 Project has not signed or included provenance with any releases.
Pinned-Dependencies 0 dependency not pinned by hash detected -- score normalized to 0
SAST 0 SAST tool is not run on all commits -- score normalized to 0

OpenSSF Badge

OpenSSF none

Badge indicates adherence to open-source best practices.

2 open CVEs against statping-ng

Sorted by KEV-listed first, then longest exposure.
CVE Severity CVSS EPSS Days open KEV Status
CVE-2023-44487 HIGH 7.5 99%ile 968d KEV Affects vLATEST
CVE-2020-11023 MEDIUM 6.9 97%ile 497d KEV Affects vLATEST

Dependency Vulnerabilities

1675 dependencies scanned View full dependency list →

Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.

Critical

17

High

72

Medium

82

Low

24

Unknown

6

2 dependency vulnerabilities are in KEV.

CISA confirmed these vulnerabilities are actively exploited. Treat as critical priority.

Critical 17 High 72 Medium 82 Low 24 Unknown 6
CVE Severity KEV Dependency Affected version Cleared in release
CVE-2021-3918 critical json-schema 0.2.3
CVE-2021-42740 critical shell-quote 1.7.2
CVE-2021-44906 critical minimist 1.2.5
CVE-2022-0686 critical url-parse 1.4.7
CVE-2022-1650 critical eventsource 1.0.7
CVE-2022-29078 critical ejs 2.7.4
CVE-2022-37601 critical loader-utils 0.2.17
CVE-2023-45133 critical @babel/traverse 7.11.0
CVE-2024-45337 critical golang.org/x/crypto 0.4.0
CVE-2025-6545 critical pbkdf2 3.1.1
CVE-2025-6547 critical pbkdf2 3.1.1
CVE-2025-7783 critical form-data 2.3.3
CVE-2025-9287 critical cipher-base 1.0.4
CVE-2025-9288 critical sha.js 2.4.11
CVE-2026-33186 critical google.golang.org/grpc 1.28.1
GHSA-28xh-wpgr-7fm8 critical open 0.0.5
GHSA-vjh7-7g9h-fjfh critical elliptic 6.5.3
CVE-2020-26160 high github.com/dgrijalva/jwt-go 3.2.0+incompatible
CVE-2020-28469 high glob-parent 5.1.1
CVE-2020-7660 high serialize-javascript 2.1.2
CVE-2020-7720 high node-forge 0.9.0
CVE-2020-7753 high trim 0.0.1
CVE-2020-7774 high y18n 4.0.0
CVE-2020-7788 high ini 1.3.5
CVE-2021-23337 high lodash 4.17.19
CVE-2021-23386 high dns-packet 1.3.1
CVE-2021-23424 high ansi-html 0.0.7
CVE-2021-27290 high ssri 5.3.0
CVE-2021-28092 high is-svg 3.0.0
CVE-2021-29059 high is-svg 3.0.0
CVE-2021-33623 high trim-newlines 3.0.0
CVE-2021-3749 high axios 0.19.2
CVE-2021-3803 high nth-check 1.0.2
CVE-2021-3807 high ansi-regex 3.0.0
CVE-2021-43138 high async 2.6.3
CVE-2022-0155 high follow-redirects 1.12.1
CVE-2022-21680 high marked 0.3.19
CVE-2022-21681 high marked 0.3.19
CVE-2022-21698 high github.com/prometheus/client_golang 1.1.0
CVE-2022-24771 high node-forge 0.9.0
CVE-2022-24772 high node-forge 0.9.0
CVE-2022-24999 high qs 6.5.2
CVE-2022-25858 high terser 4.8.0
CVE-2022-25883 high semver 7.0.0
CVE-2022-3517 high minimatch 3.0.4
CVE-2022-37599 high loader-utils 1.4.0
CVE-2022-37603 high loader-utils 1.4.0
CVE-2022-37620 high html-minifier 3.5.21
CVE-2022-38900 high decode-uri-component 0.2.0
CVE-2022-41723 high golang.org/x/net 0.4.0
CVE-2022-46175 high json5 1.0.1
CVE-2023-39325 high golang.org/x/net 0.4.0
CVE-2023-42821 high github.com/gomarkdown/markdown 0.0.0-20221013030248-663e2500819c
CVE-2023-46234 high browserify-sign 4.2.1
CVE-2024-21536 high http-proxy-middleware 0.18.0
CVE-2024-21538 high cross-spawn 6.0.5
CVE-2024-29180 high webpack-dev-middleware 3.7.2
CVE-2024-29415 high ip 1.1.5
CVE-2024-37890 high ws 6.2.1
CVE-2024-4068 high braces 3.0.2
CVE-2024-45296 high path-to-regexp 0.1.7
CVE-2024-45590 high body-parser 1.19.0
CVE-2024-52798 high path-to-regexp 0.1.7
CVE-2025-12816 high node-forge 0.9.0
CVE-2025-22868 high golang.org/x/oauth2 0.0.0-20200107190931-bf48bf16ab8d
CVE-2025-22869 high golang.org/x/crypto 0.4.0
CVE-2025-27152 high axios 0.19.2
CVE-2025-65637 high github.com/sirupsen/logrus 1.6.0
CVE-2025-66031 high node-forge 0.9.0
CVE-2026-25639 high axios 0.19.2
CVE-2026-26996 high minimatch 3.0.4
CVE-2026-27903 high minimatch 3.0.4
CVE-2026-27904 high minimatch 3.0.4
CVE-2026-32141 high flatted 2.0.2
CVE-2026-33228 high flatted 2.0.2
CVE-2026-33671 high picomatch 2.2.2
CVE-2026-33891 high node-forge 0.9.0
CVE-2026-33894 high node-forge 0.9.0
CVE-2026-33895 high node-forge 0.9.0
CVE-2026-33896 high node-forge 0.9.0
CVE-2026-40611 high github.com/go-acme/lego/v3 3.7.0
CVE-2026-40890 high github.com/gomarkdown/markdown 0.0.0-20221013030248-663e2500819c
CVE-2026-42033 high axios 0.19.2
CVE-2026-42035 high axios 0.19.2
CVE-2026-42043 high axios 0.19.2
CVE-2026-4800 high lodash 4.17.19
CVE-2026-4867 high path-to-regexp 0.1.7
GHSA-5c6j-r48x-rmvq high serialize-javascript 2.1.2
GHSA-m425-mq94-257g high google.golang.org/grpc 1.28.1
CVE-2015-9251 medium jquery 2.2.4
CVE-2019-11358 medium jquery 2.2.4
CVE-2019-16769 medium serialize-javascript 1.9.1
CVE-2020-11022 medium jquery 2.2.4
CVE-2020-11023 medium KEV jquery 2.2.4
CVE-2020-28168 medium axios 0.19.2
CVE-2020-28498 medium elliptic 6.5.3
CVE-2020-28500 medium lodash 4.17.19
CVE-2020-7608 medium yargs-parser 11.1.1
CVE-2020-7693 medium sockjs 0.3.19
CVE-2020-7760 medium codemirror 5.56.0
CVE-2020-8911 medium github.com/aws/aws-sdk-go 1.30.20
CVE-2021-23327 medium apexcharts 3.23.0
CVE-2021-23343 medium path-parse 1.0.6
CVE-2021-23362 medium hosted-git-info 2.8.8
CVE-2021-23364 medium browserslist 4.14.0
CVE-2021-23368 medium postcss 7.0.32
CVE-2021-23382 medium postcss 7.0.32
CVE-2021-27515 medium url-parse 1.4.7
CVE-2021-29060 medium color-string 1.5.3
CVE-2021-32640 medium ws 6.2.1
CVE-2021-3664 medium url-parse 1.4.7
CVE-2022-0122 medium node-forge 0.9.0
CVE-2022-0512 medium url-parse 1.4.7
CVE-2022-0536 medium follow-redirects 1.12.1
CVE-2022-0639 medium url-parse 1.4.7
CVE-2022-0691 medium url-parse 1.4.7
CVE-2022-24773 medium node-forge 0.9.0
CVE-2022-2582 medium github.com/aws/aws-sdk-go 1.30.20
CVE-2023-26115 medium word-wrap 1.2.3
CVE-2023-26136 medium tough-cookie 3.0.1
CVE-2023-26159 medium follow-redirects 1.12.1
CVE-2023-28155 medium request 2.88.2
CVE-2023-3978 medium golang.org/x/net 0.4.0
CVE-2023-44270 medium postcss 7.0.32
CVE-2023-44487 medium KEV golang.org/x/net 0.4.0
CVE-2023-45288 medium golang.org/x/net 0.4.0
CVE-2023-45857 medium axios 0.19.2
CVE-2023-48795 medium golang.org/x/crypto 0.4.0
CVE-2024-24786 medium google.golang.org/protobuf 1.25.0
CVE-2024-28180 medium gopkg.in/square/go-jose.v2 2.5.0
CVE-2024-28849 medium follow-redirects 1.12.1
CVE-2024-29041 medium express 4.17.1
CVE-2024-33883 medium ejs 2.7.4
CVE-2024-4067 medium micromatch 4.0.2
CVE-2024-44337 medium github.com/gomarkdown/markdown 0.0.0-20221013030248-663e2500819c
CVE-2024-6104 medium github.com/hashicorp/go-retryablehttp 0.6.6
CVE-2024-6485 medium bootstrap 3.4.1
CVE-2024-6783 medium vue-template-compiler 2.6.11
CVE-2025-13465 medium lodash 4.17.19
CVE-2025-15284 medium qs 6.5.2
CVE-2025-1647 medium bootstrap 3.4.1
CVE-2025-22870 medium golang.org/x/net 0.4.0
CVE-2025-22872 medium golang.org/x/net 0.4.0
CVE-2025-27789 medium @babel/runtime 7.11.2
CVE-2025-27789 medium @babel/helpers 7.10.4
CVE-2025-27789 medium @babel/runtime-corejs2 7.11.2
CVE-2025-30359 medium webpack-dev-server 3.11.0
CVE-2025-30360 medium webpack-dev-server 3.11.0
CVE-2025-47914 medium golang.org/x/crypto 0.4.0
CVE-2025-58181 medium golang.org/x/crypto 0.4.0
CVE-2025-62718 medium axios 0.19.2
CVE-2025-64718 medium js-yaml 3.13.1
CVE-2025-66030 medium node-forge 0.9.0
CVE-2025-69873 medium ajv 6.12.3
CVE-2026-2739 medium bn.js 5.1.2
CVE-2026-2950 medium lodash 4.17.19
CVE-2026-33532 medium yaml 1.10.0
CVE-2026-33672 medium picomatch 2.2.2
CVE-2026-33750 medium brace-expansion 1.1.11
CVE-2026-34043 medium serialize-javascript 2.1.2
CVE-2026-40175 medium axios 0.19.2
CVE-2026-41305 medium postcss 7.0.32
CVE-2026-42034 medium axios 0.19.2
CVE-2026-42036 medium axios 0.19.2
CVE-2026-42038 medium axios 0.19.2
CVE-2026-42039 medium axios 0.19.2
CVE-2026-42041 medium axios 0.19.2
CVE-2026-42042 medium axios 0.19.2
GHSA-7wwv-vh3v-89cq medium highlight.js 9.18.3
GHSA-r4q5-vmmm-2653 medium follow-redirects 1.12.1
GHSA-xf5p-87ch-gxw2 medium marked 0.3.19
CVE-2017-16137 low debug 4.1.1
CVE-2020-8912 low github.com/aws/aws-sdk-go 1.30.20
CVE-2023-42282 low ip 1.1.5
CVE-2024-42459 low elliptic 6.5.3
CVE-2024-42460 low elliptic 6.5.3
CVE-2024-42461 low elliptic 6.5.3
CVE-2024-43796 low express 4.17.1
CVE-2024-43799 low send 0.17.1
CVE-2024-43800 low serve-static 1.14.1
CVE-2024-47764 low cookie 0.4.0
CVE-2024-48948 low elliptic 6.5.3
CVE-2024-48949 low elliptic 6.5.3
CVE-2024-9506 low vue 2.6.11
CVE-2025-14505 low elliptic 6.5.3
CVE-2025-54798 low tmp 0.0.33
CVE-2025-54799 low github.com/go-acme/lego/v3 3.7.0
CVE-2025-5889 low brace-expansion 1.1.11
CVE-2025-7339 low on-headers 1.0.2
CVE-2026-2391 low qs 6.7.0
CVE-2026-24001 low diff 3.5.0
CVE-2026-42040 low axios 0.19.2
GHSA-5rrq-pxf6-6jx5 low node-forge 0.9.0
GHSA-gf8q-jrpm-jvxq low node-forge 0.9.0
GHSA-wxgw-qj99-44c2 low node-forge 0.9.0
CVE-2024-45338 unknown golang.org/x/net 0.4.0
CVE-2025-47911 unknown golang.org/x/net 0.4.0
CVE-2025-47913 unknown golang.org/x/crypto 0.4.0
CVE-2025-58190 unknown golang.org/x/net 0.4.0
CVE-2026-33814 unknown golang.org/x/net 0.4.0
GO-2023-2153 unknown google.golang.org/grpc 1.28.1

Showing 201 of 201

Beta — feedback welcome: [email protected]