npm vulnerability intelligence

ini NPM Package
Vulnerability Check

An ini encoder/decoder for node

High severity ISC v7.0.0
Vulnerability Analysis OSV Live

ini

v7.0.0 · ISC · 139,795,817 dl/wk

Advisory Breakdown

Critical 0
High 1
Moderate 0
Low 0

Severity Rating

High severity

1 advisory

High severity

Weekly downloads

139,795,817

Total advisories

1

Latest version

7.0.0

License

ISC

Known advisories

OSV records for the npm ecosystem

1
GHSA-qqgx-2p2h-9c37 CVE-2020-7788 high

ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

Affected: >=0 <1.3.6 Fixed in: 1.3.6 Updated Mar 13, 2026
View source

Checked Aug 12, 2026, 6:11 AM from npm and OSV.dev

Package metadata

From the npm registry

Package name
ini
Ecosystem
npm
Latest version
7.0.0
License
ISC
Weekly downloads
139,795,817

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 8/12/2026, 6:11:34 AM