Authentication for the Web.
@auth/[email protected] is safe to use (health: 91/100)
Update to >= 4.24.15 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | GHSA-x445-f3h2-j279 | Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them | 4.24.15 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@auth/coreFirst published · 2022-12-13T18:33:18.107Z
Last updated · 2026-07-20T21:52:05.342Z